Falhas do tipo CWE-22

5.902 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-6321HIGHfast-uri vulnerable to path traversal via percent-encoded dot segmentsEPSS 0.8%CVE-2026-30278CRITICALAn arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files viaEPSS 0.8%CVE-2024-27575HIGHINOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as wEPSS 0.8%CVE-2026-40491MEDIUMgdown Affected by Arbitrary File Write via Path Traversal in gdown.extractallEPSS 0.8%CVE-2025-26615CRITICALPath Traversal endpoint 'examples.php' parameter 'src' in WeGIAEPSS 0.8%CVE-2025-6465MEDIUMPath traversal in image upload with preview overwriteEPSS 0.8%CVE-2025-1543MEDIUMiteachyou Dreamer CMS ueditor-1.4.3.3 path traversalEPSS 0.8%CVE-2024-53523HIGHJSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.EPSS 0.8%CVE-2023-6190CRITICALAuthenicated Path Traversal in İzmir Katip Çelebi UniversityEPSS 0.8%CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2025-0818MEDIUMMultiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File DeletionEPSS 0.8%CVE-2026-75482HIGHSWE-agent Trajectory Inspector Path Traversal File DisclosureEPSS 0.8%CVE-2026-1311HIGHWorry Proof Backup <= 0.2.4 - Authenticated (Subscriber+) Path Traversal via Backup UploadEPSS 0.8%CVE-2023-28833LOWUnrestricted filenames for logo or favicon as admin in the theming settings in nextcloud serverEPSS 0.8%CVE-2026-75594HIGHKirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlingEPSS 0.8%CVE-2025-70796HIGHAn unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 20EPSS 0.8%CVE-2025-10236MEDIUMbinary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversalEPSS 0.8%CVE-2023-25804HIGHRoxy-WI vulnerable to Limited Path Traversal in name parameterEPSS 0.8%CVE-2023-45382HIGHIn the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal informaEPSS 0.8%CVE-2025-25295HIGHLabel Studio has a Path Traversal Vulnerability via image FieldEPSS 0.8%