Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2023-29635CRITICALFile upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to functiEPSS 1.1%CVE-2020-20735CRITICALFile Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.EPSS 1.1%CVE-2023-39970—Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.0EPSS 1.1%CVE-2023-39346HIGHbjrjk/LinuxASMCallGraph before commit 20dba06 allows attackers to cause a RCE on the server side via uploading a crafted ZIP file due to incorrect filtering rules of uploaded fileEPSS 1.1%CVE-2022-43306HIGHThe d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2026-6933HIGHPremmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin CreationEPSS 1.1%CVE-2022-45476CRITICALTiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for downloadEPSS 1.1%CVE-2022-41533HIGHOnline Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/EPSS 1.0%CVE-2024-43249CRITICALWordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2023-4186MEDIUMSourceCodester Pharmacy Management System manage_website.php unrestricted uploadEPSS 1.0%CVE-2023-22851HIGHTiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.EPSS 1.0%CVE-2024-49607CRITICALWordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2022-42198HIGHIn Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.EPSS 1.0%CVE-2024-2690MEDIUMSourceCodester Online Discussion Forum Site uupdate.php unrestricted uploadEPSS 1.0%CVE-2026-18351CRITICALDrag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' ParameterEPSS 1.0%CVE-2022-32177CRITICALGin-vue-admin - Unrestricted File UploadEPSS 1.0%CVE-2022-32176CRITICALGin-vue-admin - Unrestricted File UploadEPSS 1.0%CVE-2022-42201HIGHSimple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.EPSS 1.0%CVE-2023-5965MEDIUMUnrestricted Upload of File with Dangerous Type in EspoCRMEPSS 1.0%CVE-2023-5966MEDIUMUnrestricted Upload of File with Dangerous Type in EspoCRMEPSS 1.0%