Fallos del tipo CWE-22

5880 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-8581CRITICALPath Traversal in parisneo/lollms-webuiEPSS 1.0%CVE-2021-31156HIGHAllied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.EPSS 1.0%CVE-2023-2196MEDIUMMissing permission checks in Code Dx Plugin EPSS 1.0%CVE-2024-3195MEDIUMMailCleaner Admin Endpoints path traversalEPSS 1.0%CVE-2024-47253HIGHIn 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to EPSS 1.0%CVE-2025-42946MEDIUMDirectory Traversal vulnerability in SAP S/4HANA (Bank Communication Management)EPSS 1.0%CVE-2023-33524MEDIUMAdvent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumerates Contact informaEPSS 1.0%CVE-2021-38693MEDIUMPath Traversal in thttpdEPSS 1.0%CVE-2023-53944HIGHEasyPHP Webserver 14.1 Path Traversal via Directory Traversal SequencesEPSS 1.0%CVE-2026-6248HIGHwpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File PathEPSS 0.9%CVE-2023-23888HIGHWordPress Rank Math SEO plugin <= 1.0.107.2 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2023-48848HIGHAn arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a craftEPSS 0.9%CVE-2025-14850HIGHAdvantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted DirectoryEPSS 0.9%CVE-2022-45290CRITICALKbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.EPSS 0.9%CVE-2022-23767HIGHSecureGate authentication bypass vulnerabilityEPSS 0.9%CVE-2022-41951HIGHOroPlatform vulnerable to path traversal during temporary file manipulationsEPSS 0.9%CVE-2026-24478HIGHAnythingLLM vulnerable to Path TraversalEPSS 0.9%CVE-2024-7741MEDIUMwanglongcn ltcms API Endpoint downloadfile downloadFile path traversalEPSS 0.9%CVE-2023-39339MEDIUMA vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary fiEPSS 0.9%CVE-2024-21547HIGHVersions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where EPSS 0.9%