Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2017-20224CRITICALTelesquare SKT LTE Router SDT-CS3B1 WebDAV Arbitrary File UploadEPSS 1.0%CVE-2026-27947CRITICALGroup-Office Vulnerable to Remote Code Execution (RCE)EPSS 1.0%CVE-2022-40217MEDIUMWordPress WPide plugin <= 2.6 - Authenticated Arbitrary File Edit/Upload vulnerabilityEPSS 1.0%CVE-2024-4349HIGHSourceCodester Pisay Online E-Learning System controller.php unrestricted uploadEPSS 1.0%CVE-2026-12872CRITICALWebinfos <= 1.2 - Unauthenticated Arbitrary File UploadEPSS 1.0%CVE-2024-50427CRITICALWordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2024-0800HIGHAuthentication Bypass via wizardLogin in Arcserve Unified Data ProtectionEPSS 1.0%CVE-2023-35189CRITICALIagona ScrutisWeb Unrestricted Upload of File with Dangerous TypeEPSS 1.0%CVE-2023-23135HIGHAn arbitrary file upload vulnerability in Ftdms v3.1.6 allows attackers to execute arbitrary code via uploading a crafted JPG file.EPSS 1.0%CVE-2023-29268CRITICALTIBCO Spotfire Statistics Services Unrestricted File Upload VulnerabilityEPSS 1.0%CVE-2022-3478MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.EPSS 1.0%CVE-2024-13359HIGHProduct Input Fields for WooCommerce <= 1.12.0 - Unauthenticated Limited File UploadEPSS 1.0%CVE-2022-43275HIGHCanteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.EPSS 1.0%CVE-2024-6828HIGHRedux Framework 4.4.12 - 4.4.17 - Unauthenticated JSON File Upload to Stored Cross-Site ScriptingEPSS 1.0%CVE-2022-43061HIGHOnline Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/EPSS 1.0%CVE-2022-43277HIGHCanteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. TEPSS 1.0%CVE-2025-67886MEDIUMBitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload EPSS 1.0%CVE-2022-43050HIGHOnline Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profiEPSS 1.0%CVE-2026-14489HIGHWHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' ParameterEPSS 1.0%CVE-2026-14498HIGHQuery Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' ParameterEPSS 1.0%