Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2023-6902MEDIUMcodelyfe Stupid Simple CMS upload.php unrestricted uploadEPSS 1.0%CVE-2024-57169CRITICALA file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attacEPSS 1.0%CVE-2025-34195HIGHVasion Print (formerly PrinterLogic) Unquoted Path During Driver Installation Leads to Execution of C:\Program.exeEPSS 1.0%CVE-2025-2512CRITICALFile Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated File Upload via upload FunctionEPSS 1.0%CVE-2023-1731HIGHImproper Input Validation in Meinberg LTOSEPSS 1.0%CVE-2024-6315HIGHBlox Page Builder <= 1.0.65 - Authenticated (Contributor+) Arbitrary File UploadEPSS 1.0%CVE-2022-0959—A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manuaEPSS 1.0%CVE-2023-6308MEDIUMXiamen Four-Faith Video Surveillance Management System Apache Struts unrestricted uploadEPSS 1.0%CVE-2023-24517MEDIUMRemote Code Execution via Unrestricted File UploadEPSS 1.0%CVE-2025-13516HIGHSureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File UploadEPSS 1.0%CVE-2022-50893CRITICALVIAVIWEB Wallpaper Admin 1.0 - Code Execution via Image UploadEPSS 1.0%CVE-2025-3783MEDIUMSourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted uploadEPSS 1.0%CVE-2024-41577CRITICALAn arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploEPSS 1.0%CVE-2025-22654CRITICALWordPress Simplified Plugin Plugin <= 1.0.6 - Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2024-40645HIGHFOG Authenticated File Upload RCEEPSS 1.0%CVE-2026-18391CRITICALWooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object InjectionEPSS 1.0%CVE-2024-9307CRITICALmFolio Lite <= 1.2.1 - Missing Authorization to Authenticated (Author+) File Upload via EXE and SVG FilesEPSS 1.0%CVE-2024-3242HIGHBrizy – Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File UploadEPSS 1.0%CVE-2023-24202CRITICALRaffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.EPSS 1.0%CVE-2023-0924HIGHZyrex Popup <= 1.0 - Admin+ Arbitrary File UploadEPSS 1.0%