Weaknesses of type CWE-434

3,089 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2022-46604HIGHAn issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a craftEPSS 8.6%CVE-2021-24160—Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File UploadEPSS 8.2%CVE-2021-27274CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System EPSS 8.2%CVE-2021-24212—WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCEEPSS 7.9%CVE-2021-22937—A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously cEPSS 7.8%CVE-2016-15043CRITICALWP Mobile Detector <= 3.5 - Arbitrary File UploadEPSS 7.8%CVE-2022-34128CRITICALThe Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.EPSS 7.8%CVE-2021-24236—Imagements <= 1.2.5 - Unauthenticated Arbitrary File Upload to RCEEPSS 7.3%CVE-2020-36849CRITICALAIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File UploadEPSS 7.0%CVE-2020-36705CRITICALAdning Advertising <= 1.5.5 - Arbitrary File UploadEPSS 6.9%CVE-2021-34624CRITICALProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader ComponentEPSS 6.7%CVE-2017-3189—The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file uploadEPSS 6.5%CVE-2026-53787CRITICALAmasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File UploadEPSS 6.5%CVE-2020-20969HIGHFile Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.EPSS 6.2%CVE-2026-15748CRITICALForminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field ConfigurationEPSS 6.1%CVE-2024-2561MEDIUM74CMS Company Logo Index.php#sendCompanyLogo unrestricted uploadEPSS 6.1%CVE-2021-37608—Arbitrary file upload vulnerability in OFBizEPSS 6.0%CVE-2023-5144MEDIUMD-Link DAR-7000/DAR-8000 updateos.php unrestricted uploadEPSS 6.0%CVE-2025-3515HIGHDrag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist ChecksEPSS 5.8%CVE-2024-2667CRITICALInstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File UploadEPSS 5.8%