Fallos del tipo CWE-22

5867 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-4098CRITICALShariff Wrapper <= 4.6.13 - Unauthenticated Local File InclusionEPSS 1.0%CVE-2025-11849MEDIUMVersions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of thEPSS 1.0%CVE-2024-50648CRITICALyshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to pEPSS 1.0%CVE-2023-53902HIGHWebsiteBaker 2.13.3 Directory Traversal via Media Delete EndpointEPSS 1.0%CVE-2025-3520HIGHAvatar <= 0.1.4 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 1.0%CVE-2024-8671CRITICALWooEvents <= 4.1.2 - Unauthenticated Arbitrary File OverwriteEPSS 1.0%CVE-2024-39330MEDIUMAn issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base clasEPSS 1.0%CVE-2026-27699CRITICALBasic FTP has Path Traversal Vulnerability in its downloadToDir() methodEPSS 1.0%CVE-2026-78657CRITICALSigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload FieldEPSS 1.0%CVE-2022-46171MEDIUMTauri vulnerable to path traversalEPSS 1.0%CVE-2023-30172HIGHA directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary fEPSS 1.0%CVE-2024-5147CRITICALWPZOOM Addons for Elementor (Templates, Widgets) <= 1.1.37 - Unauthenticated Local File InclusionEPSS 1.0%CVE-2024-34060HIGHArbitrary File Write in IRIS EVTX PipelineEPSS 1.0%CVE-2025-24888HIGHPath traversal in SecureDrop Client API.download_reply()EPSS 1.0%CVE-2026-45230HIGHDumbAssets 1.0.11 Path Traversal File Deletion via /api/delete-fileEPSS 1.0%CVE-2026-18352HIGHUser Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' ParameterEPSS 1.0%CVE-2022-1850MEDIUMPath Traversal in filegator/filegatorEPSS 1.0%CVE-2024-6707HIGHOpen WebUI Arbitrary File Upload + Path TraversalEPSS 1.0%CVE-2023-45686HIGHArbitrary file write via WebDAV path traversal in Titan MFT and Titan SFTP serversEPSS 1.0%CVE-2024-5153CRITICALStartklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory DeletionEPSS 1.0%