Fallos del tipo CWE-434

3093 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2025-0341MEDIUMCampCodes Computer Laboratory Management System edit unrestricted uploadEPSS 0.5%CVE-2025-54442CRITICALUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affEPSS 0.5%CVE-2025-5130MEDIUMTmall Demo uploadProductImage unrestricted uploadEPSS 0.5%CVE-2026-6602MEDIUMrickxy Hospital Management System his_admin_account.php unrestricted uploadEPSS 0.5%CVE-2026-5001MEDIUMPromtEngineer localGPT server.py do_POST unrestricted uploadEPSS 0.5%CVE-2026-8758MEDIUMMetasoft 美特软件 MetaCRM upload3.jsp unrestricted uploadEPSS 0.5%CVE-2024-3444MEDIUMWangshen SecGate 3600 ?g=net_pro_keyword_import_save unrestricted uploadEPSS 0.5%CVE-2026-4191MEDIUMJawherKl node-api-postgres Profile Picture index.js path.extname unrestricted uploadEPSS 0.5%CVE-2026-13547MEDIUMHanwang e-Face General Management Platform upload.do unrestricted uploadEPSS 0.5%CVE-2026-6596MEDIUMlangflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted uploadEPSS 0.5%CVE-2026-7711MEDIUMMindsDB Engine proc_wrapper.py exec unrestricted uploadEPSS 0.5%CVE-2026-5261MEDIUMShandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted uploadEPSS 0.5%CVE-2026-82921MEDIUMShopEx ECShop pack.php check_img_type unrestricted uploadEPSS 0.5%CVE-2026-95499MEDIUMJosephChuks php-file-manager-with-code-editor filemanager.php move_uploaded_file unrestricted uploadEPSS 0.5%CVE-2026-4536MEDIUMAcrel Environmental Monitoring Cloud Platform unrestricted uploadEPSS 0.5%CVE-2026-95500MEDIUMJosephChuks php-file-manager-with-code-editor Save codeEditor.php file_put_contents unrestricted uploadEPSS 0.5%CVE-2026-4221MEDIUMTiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted uploadEPSS 0.5%CVE-2026-14736MEDIUMRuijie RG-UAC user_auth_commit.php unrestricted uploadEPSS 0.5%CVE-2026-18969MEDIUMRongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted uploadEPSS 0.5%CVE-2026-16324MEDIUMMetasoft 美特软件 MetaCRM upload.jsp unrestricted uploadEPSS 0.5%