Falhas do tipo CWE-22

5.866 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-2743MEDIUMzhijiantianya ruoyi-vue-pro Material Upload Interface upload-temporary path traversalEPSS 0.9%CVE-2026-65688CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font ProcessingEPSS 0.9%CVE-2024-57451HIGHChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to EPSS 0.9%CVE-2026-65689CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database DownloadEPSS 0.9%CVE-2024-48071MEDIUME-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the serEPSS 0.9%CVE-2024-5456HIGHPanda Video <= 1.4.0 - Authenticated (Contributor+) Local File InclusionEPSS 0.9%CVE-2023-24379MEDIUMWordPress Landing Page Builder – Free Landing Page Templates plugin <= 3.1.9.9 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2025-48370LOWauth-js Vulnerable to Insecure Path Routing from Malformed User InputEPSS 0.9%CVE-2023-3385MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 0.9%CVE-2023-4748MEDIUMYongyou UFIDA-NC PrintTemplateFileServlet.java path traversalEPSS 0.9%CVE-2025-0461MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php path traversalEPSS 0.9%CVE-2025-55988HIGHAn issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via EPSS 0.9%CVE-2026-71476HIGHNx: Zip-Slip in the self-hosted remote cacheEPSS 0.9%CVE-2023-6026CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in PHPMemcachedAdminEPSS 0.9%CVE-2023-39525MEDIUMPrestaShop vulnerable to path traversalEPSS 0.9%CVE-2022-44280MEDIUMAutomotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.EPSS 0.9%CVE-2024-37464MEDIUMWordPress Beaver Builder Addons by WPZOOM plugin <= 1.3.5 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2021-39369MEDIUMIn Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to aEPSS 0.9%CVE-2022-45829HIGHWordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Arbitrary File DeletionEPSS 0.9%CVE-2026-47731CRITICALNASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)EPSS 0.9%