Falhas do tipo CWE-22

5.866 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2024-31801HIGHDirectory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive information via a crafted reEPSS 1.1%CVE-2021-21298LOWPath traversal in Node-RedEPSS 1.1%CVE-2024-6312MEDIUMFunnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File DeletionEPSS 1.1%CVE-2026-26984HIGHLORIS media module vulnerable to remote code executionEPSS 1.1%CVE-2026-15095MEDIUMProduct Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' ParameterEPSS 1.1%CVE-2025-40549CRITICALSolarWinds Serv-U Path Restriction Bypass VulnerabilityEPSS 1.1%CVE-2019-25053HIGHA path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files ouEPSS 1.1%CVE-2018-10917MEDIUMpulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to lEPSS 1.1%CVE-2026-22786HIGHGin-vue-admin has arbitrary file upload vulnerability caused by path traversalEPSS 1.1%CVE-2021-21284MEDIUMprivilege escalation in MobyEPSS 1.1%CVE-2024-50508HIGHWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Download vulnerabilityEPSS 1.1%CVE-2023-26969HIGHAtropim 1.5.26 is vulnerable to Directory Traversal.EPSS 1.1%CVE-2022-4880MEDIUMstakira OpenUtau ZIP Archive VoicebankInstaller.cs VoicebankInstaller path traversalEPSS 1.1%CVE-2021-3823HIGHPath traversal vulnerability in Bitdefender GravitZone Update Server in relay modeEPSS 1.1%CVE-2020-5720—MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has wriEPSS 1.1%CVE-2026-36500CRITICALAn issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a craftEPSS 1.1%CVE-2024-46376CRITICALBest House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/EPSS 1.1%CVE-2026-14372HIGHBit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' ParameterEPSS 1.1%CVE-2024-11642CRITICALPost Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File InclusionEPSS 1.1%CVE-2025-20374MEDIUMCisco Unified Contact Center Express Arbitrary File Download VulnerabilityEPSS 1.1%