Weaknesses of type CWE-434

3,099 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2024-25410MEDIUMflusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.EPSS 0.6%CVE-2024-35080CRITICALAn arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craftEPSS 0.6%CVE-2024-56054CRITICALWordPress WPLMS plugin < 1.9.9.5.2 - Instructor+ Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2024-35079CRITICALAn arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading EPSS 0.6%CVE-2026-93031HIGHWP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box <= 3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload via Media ImportEPSS 0.6%CVE-2023-46149CRITICALWordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File UploadEPSS 0.6%CVE-2024-46088CRITICALAn arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource ManagementEPSS 0.6%CVE-2024-33556HIGHWordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2025-0471CRITICALUnrestricted Upload of File with Dangerous Type vulnerability in PMB platformEPSS 0.6%CVE-2024-10999MEDIUMCodeAstro Real Estate Management System About Us Page aboutadd.php unrestricted uploadEPSS 0.6%CVE-2024-11000MEDIUMCodeAstro Real Estate Management System About Us Page aboutedit.php unrestricted uploadEPSS 0.6%CVE-2025-69559CRITICALcode-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.EPSS 0.6%CVE-2025-11675HIGHRagic|Enterprise Cloud Database - Arbitrary File UploadEPSS 0.6%CVE-2025-6222CRITICALWooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File UploadEPSS 0.6%CVE-2024-0933MEDIUMNiushop B2B2C Upload.php unrestricted uploadEPSS 0.6%CVE-2024-42767HIGHKashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.EPSS 0.6%CVE-2025-0722MEDIUMneedyamin image_gallery Cover Image gallery.php unrestricted uploadEPSS 0.6%CVE-2024-9975MEDIUMSourceCodester Drag and Drop Image Upload upload.php unrestricted uploadEPSS 0.6%CVE-2023-6675CRITICALMalicious File Upload in National Keep's CyberMathEPSS 0.6%CVE-2023-7036MEDIUMautomad Content Type FileCollectionController.php upload unrestricted uploadEPSS 0.6%