Falhas do tipo CWE-22

5.906 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-12000MEDIUMWPFunnels <= 3.6.2 - Authenticated (Administrator+) Arbitrary File Deletion via Path TraversalEPSS 0.7%CVE-2026-76652MEDIUMAuthenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600EPSS 0.7%CVE-2026-11974HIGHMedia folder Addon < 4.1.7 - Unauthenticated Arbitrary File DownloadEPSS 0.7%CVE-2024-2224HIGHPrivilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)EPSS 0.7%CVE-2026-3087MEDIUMshutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsEPSS 0.7%CVE-2025-64075CRITICALA path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to EPSS 0.7%CVE-2025-2744MEDIUMzhijiantianya ruoyi-vue-pro Material Upload Interface upload-news-image path traversalEPSS 0.7%CVE-2025-6776MEDIUMxiaoyunjie openvpn-cms-flask File Upload controller.py upload path traversalEPSS 0.7%CVE-2025-67653MEDIUMAdvantech WebAccess/SCADA Path TraversalEPSS 0.7%CVE-2023-49793MEDIUMPath traversal in `CodeChecker server` in the endpoint of `CodeChecker store`EPSS 0.7%CVE-2025-8729MEDIUMMigoXLab LMeterX upload_service.py process_cert_files path traversalEPSS 0.7%CVE-2025-15449MEDIUMcld378632668 JavaMall MinioController.java delete path traversalEPSS 0.7%CVE-2025-47176HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-24689MEDIUMAn issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via mEPSS 0.7%CVE-2025-10176HIGHThe Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File DeletionEPSS 0.7%CVE-2022-38731MEDIUMQaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbiEPSS 0.7%CVE-2025-59352MEDIUMDragonfly allows arbitrary file read and write on a peer machineEPSS 0.7%CVE-2025-61557HIGHnixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.EPSS 0.7%CVE-2023-22320HIGHOpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerEPSS 0.7%CVE-2024-25659HIGHIn Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux serveEPSS 0.7%