Falhas do tipo CWE-22

5.880 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-40982CRITICALSpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious EPSS 0.8%CVE-2023-53979HIGHMyBB 1.8.32 Authenticated Remote Code Execution via Chained VulnerabilitiesEPSS 0.8%CVE-2024-34245MEDIUMAn arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in maEPSS 0.8%CVE-2024-46647MEDIUMeNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.EPSS 0.8%CVE-2023-3348MEDIUMDirectory traversal vulnerability in Cloudflare WranglerEPSS 0.8%CVE-2025-7712CRITICALMadara - Core <= 2.2.3 - Unauthenticated Arbitrary File DeletionEPSS 0.8%CVE-2024-1165MEDIUMBrizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory TraversalEPSS 0.8%CVE-2026-40909HIGHWWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)EPSS 0.8%CVE-2023-43044MEDIUMIBM License Metric Tool directory traversalEPSS 0.8%CVE-2025-67171HIGHIncorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.EPSS 0.8%CVE-2023-45689—Arbitrary file read via path traversal in Titan MFT and Titan SFTP serversEPSS 0.8%CVE-2025-30895HIGHWordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerabilityEPSS 0.8%CVE-2025-3055HIGHWP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.8%CVE-2025-50349HIGHPHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.EPSS 0.8%CVE-2023-7309CRITICALDahua Smart Park Integrated Management Platform Front-End Arbitrary File UploadEPSS 0.8%CVE-2026-3864MEDIUMCSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS serverEPSS 0.8%CVE-2023-25914HIGHAuthneticated Path Traversal in Danfoss AK-SM800AEPSS 0.8%CVE-2021-37532MEDIUMSAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the conteEPSS 0.8%CVE-2025-64057HIGHDirectory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrarEPSS 0.8%CVE-2023-53907HIGHBludit 3.13.1 Authenticated Arbitrary File Download via Backup PluginEPSS 0.8%