Fallos del tipo CWE-22

5873 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-31450LOWOwncast vulnerable to arbitrary file deletion in emoji.go (GHSL-2023-277)EPSS 1.0%CVE-2026-4758HIGHWP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File FieldEPSS 1.0%CVE-2015-10105MEDIUMIP Blacklist Cloud Plugin CSV File Import ip_blacklist_cloud.php valid_js_identifier path traversalEPSS 1.0%CVE-2026-54629HIGHAnyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeEPSS 1.0%CVE-2026-7565MEDIUMLearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' ParameterEPSS 1.0%CVE-2022-43264HIGHArobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via EPSS 1.0%CVE-2024-25461HIGHDirectory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive informationEPSS 1.0%CVE-2023-25815LOWGit looks for localized messages in the wrong placeEPSS 1.0%CVE-2026-19952HIGHFrontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge TagEPSS 1.0%CVE-2026-82954CRITICALDokploy Settings application.ts writeTraefikConfigInPath path traversalEPSS 1.0%CVE-2024-38449HIGHA Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote auEPSS 1.0%CVE-2025-34350HIGHUnForm Server < 10.1.15 Doc Flow Unauthenticated File ReadEPSS 1.0%CVE-2023-3241LOWOTCMS path traversalEPSS 1.0%CVE-2022-39812HIGHItaltel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload EPSS 1.0%CVE-2024-13897MEDIUMMoving Media Library <= 1.22 - Authenticated (Administrator+) Directory Traversal to Arbitrary File DeletionEPSS 1.0%CVE-2022-2653HIGHPath Traversal in plankanban/plankaEPSS 1.0%CVE-2026-93643CRITICALZimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas RequestEPSS 1.0%CVE-2022-24731MEDIUMPath traversal allows leaking out-of-bound files from Argo CD repo-serverEPSS 1.0%CVE-2024-8352HIGHSocial Web Suite – Social Media Auto Post, Social Media Auto Publish <= 4.1.11 - Directory Traversal to Arbitrary File DownloadEPSS 1.0%CVE-2023-53772HIGHMiniDVBLinux 5.4 Arbitrary File Read Vulnerability via About PageEPSS 1.0%