Weaknesses of type CWE-434

3,093 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2021-47753CRITICALphpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)EPSS 0.8%CVE-2022-42029HIGHChamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big fileEPSS 0.8%CVE-2023-5829MEDIUMcode-projects Admission Management System student_avatar.php unrestricted uploadEPSS 0.8%CVE-2023-5795MEDIUMCodeAstro POS System Profile Picture profil unrestricted uploadEPSS 0.8%CVE-2025-63228CRITICALThe Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /EPSS 0.8%CVE-2024-11984CRITICALSUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous TypeEPSS 0.8%CVE-2026-66270HIGHDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A hiEPSS 0.8%CVE-2025-1028HIGHContact Manager <= 8.6.4 - Unauthenticated Arbitrary Double File Extension UploadEPSS 0.8%CVE-2026-66271HIGHDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A hiEPSS 0.8%CVE-2026-45053CRITICALCubeCart: Authenticated Arbitrary File Upload to RCE in REST Files APIEPSS 0.8%CVE-2026-30804HIGHUnrestricted File Upload in Extension Uploader leads to Remote Code ExecutionEPSS 0.8%CVE-2026-58409CRITICALChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin UploadEPSS 0.8%CVE-2026-14946HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious configuration file.EPSS 0.8%CVE-2026-3418CRITICALArbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.8%CVE-2022-1411CRITICALUnrestructed file upload in yetiforcecompany/yetiforcecrmEPSS 0.8%CVE-2024-29891HIGHZITADEL Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP BypassEPSS 0.8%CVE-2023-34126—Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileEPSS 0.8%CVE-2026-1331CRITICALAMASTAR Technology|MeetingHub - Arbitrary File UploadEPSS 0.8%CVE-2024-13882HIGHAiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File UploadEPSS 0.8%CVE-2024-29368MEDIUMAn arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via fEPSS 0.8%