Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2023-7091MEDIUMDreamer CMS uploadFile unrestricted uploadEPSS 0.9%CVE-2025-29017HIGHA Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in theEPSS 0.9%CVE-2022-0951HIGHFile Upload Restriction Bypass leading to Stored XSS Vulnerability in star7th/showdocEPSS 0.9%CVE-2025-55835CRITICALFile Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.EPSS 0.9%CVE-2023-2424MEDIUMDedeCMS config.php UpDateMemberModCache unrestricted uploadEPSS 0.9%CVE-2023-1501MEDIUMRockOA acloudCosAction.php.SQL runAction unrestricted uploadEPSS 0.9%CVE-2024-40125CRITICALAn arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execuEPSS 0.9%CVE-2023-4409MEDIUMNBS&HappySoftWeChat unrestricted uploadEPSS 0.9%CVE-2025-34046CRITICALFanwei E-Office Unauthenticated File UploadEPSS 0.9%CVE-2024-36415CRITICALSuiteCRM Improper Control of Filename for Include Statement in PHP and Unrestricted Upload of File with Dangerous content leads to authenticated remote code executionEPSS 0.9%CVE-2023-41506CRITICALAn arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackEPSS 0.9%CVE-2024-56828CRITICALFile Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoiEPSS 0.9%CVE-2026-33435HIGHWeblate: Remote code execution during backup restorationEPSS 0.9%CVE-2025-2006HIGHInline Image Upload for BBPress <= 1.1.19 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2025-9216HIGHStoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2025-26350MEDIUMA CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.1EPSS 0.9%CVE-2023-3797MEDIUMGen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System UploadFloodPlanFileUpdate.ashx unrestricted uploadEPSS 0.9%CVE-2023-0783MEDIUMEcShop PHP File template.php unrestricted uploadEPSS 0.9%CVE-2024-4966MEDIUMSourceCodester SchoolWebTech home.php unrestricted uploadEPSS 0.9%CVE-2024-56264MEDIUMWordPress ACF City Selector plugin <= 1.14.0 - Arbitrary File Upload vulnerabilityEPSS 0.9%