Weaknesses of type CWE-434

3,090 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2023-46808CRITICALAn file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. SuccessEPSS 2.0%CVE-2023-27602CRITICALApache Linkis publicsercice module unrestricted upload of fileEPSS 2.0%CVE-2023-26852HIGHAn arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by upEPSS 2.0%CVE-2015-1784—In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weEPSS 2.0%CVE-2024-34833CRITICALSourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unautheEPSS 2.0%CVE-2021-24493—Shopp eCommerce <= 1.4 - Unauthenticated Arbitrary File UploadEPSS 2.0%CVE-2025-32028CRITICALHAX CMS PHP allows Insecure File Upload to Lead to Remote Code ExecutionEPSS 2.0%CVE-2013-10044HIGHOpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCEEPSS 2.0%CVE-2022-41705CRITICALBadaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because thEPSS 2.0%CVE-2021-22803—A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number ofEPSS 1.9%CVE-2020-3436HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services File Upload Denial of Service VulnerabilityEPSS 1.9%CVE-2023-33480HIGHRemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to EPSS 1.9%CVE-2026-32985CRITICALXerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code ExecutionEPSS 1.9%CVE-2026-25099HIGHRemote Code Execution via Unrestricted File Upload in BluditEPSS 1.9%CVE-2021-24253—Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCEEPSS 1.9%CVE-2021-24224—Easy Form Builder <= 1.0 - Authenticated Arbitrary File UploadEPSS 1.9%CVE-2021-24171—WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File UploadEPSS 1.9%CVE-2020-11011CRITICALRCE via file upload in PhprojectEPSS 1.9%CVE-2012-10027CRITICALWordPress Plugin WP-Property <= 1.35.0 PHP File UploadEPSS 1.9%CVE-2023-51444HIGHGeoServer arbitrary file upload vulnerability in REST Coverage Store APIEPSS 1.9%