Falhas do tipo CWE-22

5.908 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2023-30197HIGHIncorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personalEPSS 0.7%CVE-2025-4946HIGHVikinger <= 1.9.32 - Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax FunctionEPSS 0.7%CVE-2026-54053CRITICALMany Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaultsEPSS 0.7%CVE-2025-25243HIGHPath traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)EPSS 0.7%CVE-2023-30199HIGHPrestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.EPSS 0.7%CVE-2026-80156CRITICALLantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation BypassEPSS 0.7%CVE-2025-65878HIGHThe warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanEPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2024-1593HIGHPath Traversal via Parameter Smuggling in mlflow/mlflowEPSS 0.7%CVE-2025-15432MEDIUMyeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversalEPSS 0.7%CVE-2026-65701CRITICALSoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask RouteEPSS 0.7%CVE-2025-11337MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;othersusrlogout.do path traversalEPSS 0.7%CVE-2025-27716MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB stEPSS 0.7%CVE-2025-11336MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;otherlogout.do path traversalEPSS 0.7%CVE-2025-8480HIGHAlpine iLX-507 Command Injection Remote Code ExecutionEPSS 0.7%CVE-2023-7077CRITICALSharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554EPSS 0.7%CVE-2026-75602MEDIUMOpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolEPSS 0.7%CVE-2026-71475MEDIUMInsights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathEPSS 0.7%CVE-2016-10330—Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local usEPSS 0.7%CVE-2025-7098MEDIUMComodo Internet Security Premium File Name path traversalEPSS 0.7%