Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2022-1519CRITICALLRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, includingEPSS 1.4%CVE-2024-3962CRITICALProduct Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_fileEPSS 1.4%CVE-2023-49715MEDIUMA unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fEPSS 1.4%CVE-2024-0864CRITICALRCE in LaragonEPSS 1.4%CVE-2023-6558HIGHExport and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File UploadEPSS 1.4%CVE-2023-27178CRITICALAn arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted EPSS 1.4%CVE-2023-6576MEDIUMByzoro S210 HTTP POST Request uploadfile.php unrestricted uploadEPSS 1.4%CVE-2023-28353HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any locEPSS 1.4%CVE-2021-33352CRITICALAn issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar fEPSS 1.4%CVE-2009-20011CRITICALContentKeeper Web Appliance < 125.10 RCE via mimencodeEPSS 1.4%CVE-2022-23155HIGHDell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileEPSS 1.4%CVE-2024-27923HIGHRemote Code Execution by uploading a phar file using frontmatterEPSS 1.4%CVE-2024-32880CRITICALpyLoad allows upload to arbitrary folder lead to RCEEPSS 1.4%CVE-2024-31114CRITICALWordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerabilityEPSS 1.4%CVE-2026-6555CRITICALProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files'EPSS 1.4%CVE-2024-28713CRITICALAn issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.EPSS 1.3%CVE-2026-3535CRITICALDSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' ParameterEPSS 1.3%CVE-2024-11617CRITICALEnvolve Plugin <= 1.0 - Unauthenticated Arbitrary File Upload via language_file and fonts_fileEPSS 1.3%CVE-2025-55746CRITICALDirectus allows unauthenticated file upload and file modification due to lacking input sanitizationEPSS 1.3%CVE-2025-4336HIGHeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_file()EPSS 1.3%