Weaknesses of type CWE-434

3,093 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2024-8242MEDIUMMStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File UploadEPSS 0.8%CVE-2025-66449HIGHConvertX has Path Traversal that leads to Arbitrary File Write and Arbitrary Code ExecutionEPSS 0.8%CVE-2023-40183HIGHDataEase has a vulnerability to obtain user cookiesEPSS 0.8%CVE-2024-25274CRITICALAn arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code EPSS 0.8%CVE-2025-11170CRITICALWP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File UploadEPSS 0.8%CVE-2025-12674CRITICALKiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File UploadEPSS 0.8%CVE-2022-3682CRITICALSDM600 file permission validationEPSS 0.8%CVE-2023-6723CRITICALUnrestricted Upload of File with Dangerous Type in RepoxEPSS 0.8%CVE-2024-0505MEDIUMZhongFuCheng3y Austin Upload Material Menu MaterialController.java getFile unrestricted uploadEPSS 0.8%CVE-2023-5790MEDIUMSourceCodester File Manager App add-file.php unrestricted uploadEPSS 0.8%CVE-2021-3846MEDIUMUnrestricted Upload of File with Dangerous Type in firefly-iii/firefly-iiiEPSS 0.8%CVE-2026-26975HIGHMusic Assistant Server Path Traversal in Playlist Update API Allows Remote Code ExecutionEPSS 0.8%CVE-2024-28423CRITICALAirflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulneraEPSS 0.8%CVE-2024-33120CRITICALRoothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vuEPSS 0.8%CVE-2025-29287CRITICALAn arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crEPSS 0.8%CVE-2024-11979CRITICALInterinfo DreamMaker - Unrestricted File Upload through Path TraversalEPSS 0.8%CVE-2024-4197CRITICALAvaya IP Office One-X Portal File Upload VulnerabilityEPSS 0.8%CVE-2026-35164HIGHBrave CMS Sffected by Unrestricted File Upload via CKEditor EndpointEPSS 0.8%CVE-2024-38530CRITICALOpen eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"EPSS 0.8%CVE-2023-30090CRITICALSemcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability alEPSS 0.8%