Falhas do tipo CWE-22

5.866 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2022-3060HIGHImproper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attackeEPSS 1.0%CVE-2021-35968MEDIUMLearningdigital.com, Inc. Orca HCM - Path Traversal-2EPSS 1.0%CVE-2026-7311HIGHTinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post MetaEPSS 1.0%CVE-2020-24855MEDIUMDirectory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.EPSS 1.0%CVE-2026-33076HIGHRoxy-WI vulnerable to path traversal and arbitrary file writingEPSS 1.0%CVE-2024-1961HIGHPath Traversal leading to Arbitrary File Write and RCE in vertaai/modeldbEPSS 1.0%CVE-2022-47951MEDIUMAn issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.EPSS 1.0%CVE-2026-29522HIGHZwickRoell Test Data Management < 3.0.8 Path Traversal LFIEPSS 1.0%CVE-2021-33724—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File DeletionEPSS 1.0%CVE-2023-22914HIGHA path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN EPSS 1.0%CVE-2025-1336MEDIUMCmsEasy image_admin.php deleteimg_action path traversalEPSS 1.0%CVE-2026-6227HIGHBackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' ParameterEPSS 1.0%CVE-2021-33725—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files orEPSS 1.0%CVE-2018-16739HIGHAn issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, aEPSS 1.0%CVE-2017-20105MEDIUMSimplessus path traversalEPSS 1.0%CVE-2021-36288HIGHDell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/writeEPSS 1.0%CVE-2025-13645HIGHModula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File DeletionEPSS 1.0%CVE-2024-46898HIGHSHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability isEPSS 1.0%CVE-2023-23760MEDIUMPath traversal in GitHub Enterprise Server leading to remote code executionEPSS 1.0%CVE-2023-26045CRITICALNodeBB vulnerable to path traversal and code execution via prototype vulnerabilityEPSS 1.0%