Weaknesses of type CWE-434

3,089 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2024-27115CRITICALRemote Code Execution through File Upload in SOPlanning before 1.52.02EPSS 4.6%CVE-2024-43160CRITICALWordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerabilityEPSS 4.6%CVE-2021-39139HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 4.5%CVE-2026-1306CRITICALmidi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX ActionEPSS 4.5%CVE-2021-39153HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 4.5%CVE-2023-1826MEDIUMSourceCodester Online Computer and Laptop Store index.php unrestricted uploadEPSS 4.4%CVE-2021-34997HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authEPSS 4.2%CVE-2021-21014CRITICALMagento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code ExecutionEPSS 4.2%CVE-2023-52324HIGHAn unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected inEPSS 4.2%CVE-2018-25114CRITICALosCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code ExecutionEPSS 4.2%CVE-2012-10020CRITICALFoxyPress <= 0.4.2.1 - Arbitrary File UploadEPSS 4.1%CVE-2023-48777CRITICALWordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerabilityEPSS 4.1%CVE-2019-3940—Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use thiEPSS 4.1%CVE-2024-8425CRITICALWooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File UploadEPSS 4.1%CVE-2021-39145HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 4.1%CVE-2025-2749HIGHKentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCEEPSS 4.1%KEVCVE-2019-18288—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentiEPSS 4.0%CVE-2024-39717MEDIUMThe Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logEPSS 4.0%KEVCVE-2015-10135CRITICALWPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File UploadEPSS 4.0%CVE-2026-14483CRITICALRealtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' CommandEPSS 4.0%