Falhas do tipo CWE-22

5.913 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2024-32024MEDIUMKohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`)EPSS 0.7%CVE-2024-41704CRITICALLibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.EPSS 0.7%CVE-2024-24311HIGHPath Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before versEPSS 0.7%CVE-2025-41035HIGHPath Traversal vulnerability in appRain CMFEPSS 0.7%CVE-2026-66384MEDIUMAuthenticated users may write data outside the intended Docker cache pathEPSS 0.7%KEVCVE-2024-3934MEDIUMMercado Pago payments for WooCommerce 7.3.0 - 7.6.1 - Authenticated (Subscriber+) Arbitrary File DownloadEPSS 0.7%CVE-2025-10307MEDIUMBackuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File DeletionEPSS 0.7%CVE-2025-70231CRITICALD-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/EPSS 0.7%CVE-2021-46902HIGHAn issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. PathEPSS 0.7%CVE-2026-7474HIGHNomad vulnerable to path traversal in dynamic host volume which may lead to code executionEPSS 0.7%CVE-2026-50003CRITICALOFFIS DCMTK Toolkit Path TraversalEPSS 0.7%CVE-2026-54414CRITICALFileRise shared-folder upload path traversal allows arbitrary file write and admin takeoverEPSS 0.7%CVE-2026-15160MEDIUMNinja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path TraversalEPSS 0.7%CVE-2023-49960HIGHIn Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attEPSS 0.7%CVE-2023-45197CRITICALAdminer and AdminerEvo vulnerable to directory traversal and file uploadEPSS 0.7%CVE-2023-3697HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.7%CVE-2025-67030HIGHDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2dEPSS 0.7%CVE-2024-40051HIGHIP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.EPSS 0.7%CVE-2024-52883HIGHAn issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive daEPSS 0.7%CVE-2026-43637HIGHCornac < 2.6.0 Path Traversal via _extract_archive() in download.pyEPSS 0.7%