Fallos del tipo CWE-434

3099 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2025-61681MEDIUMKuno is Vulnerable to Stored XSS Attack via SVG File UploadEPSS 0.2%CVE-2026-2183MEDIUMGreat Developers Certificate Generation System csv.php unrestricted uploadEPSS 0.2%CVE-2019-25626HIGHRiver Past Cam Do 3.7.6 Local Buffer Overflow in Activation CodeEPSS 0.2%CVE-2024-34683MEDIUMUnrestricted file upload in SAP Document Builder (HTTP service)EPSS 0.2%CVE-2025-15152MEDIUMh-moses moga-mall PmsProductController.java addProduct unrestricted uploadEPSS 0.2%CVE-2025-13249MEDIUMJiusi OA OfficeServer unrestricted uploadEPSS 0.2%CVE-2025-54962MEDIUM/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), aEPSS 0.2%CVE-2025-0057MEDIUMCross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application)EPSS 0.2%CVE-2025-13949MEDIUMProudMuBai GoFilm FileController.go SingleUpload unrestricted uploadEPSS 0.2%CVE-2024-9544MEDIUMMapSVG - All Kinds of Maps and Store Locator for WordPress <= 8.6.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2024-55514MEDIUMA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.phEPSS 0.2%CVE-2025-12048HIGHAn arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allowEPSS 0.2%CVE-2025-14632MEDIUMFilr – Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML UploadEPSS 0.2%CVE-2023-37208—When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < EPSS 0.2%CVE-2026-19852MEDIUMCyberTutor|NewSiteServer (NSS) - Arbitrary File UploadEPSS 0.2%CVE-2022-45415HIGHWhen downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the fEPSS 0.2%CVE-2025-62802MEDIUMDNN CKEditor Provider allows unauthenticated upload out-of-the-boxEPSS 0.2%CVE-2022-45338HIGHAn arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact SynerEPSS 0.2%CVE-2025-55810MEDIUMA vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, whEPSS 0.2%CVE-2025-9795MEDIUMxujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted uploadEPSS 0.2%