Fallos del tipo CWE-434

3083 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2023-53922CRITICALTinyWebGallery v2.5 Remote Code Execution via Unrestricted File UploadEPSS 1.1%CVE-2021-38471CRITICALAUVESY VersiondogEPSS 1.1%CVE-2022-40925HIGHZoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" mEPSS 1.1%CVE-2023-25921HIGHIBM Security Guardium Key Lifecycle Manager file uploadEPSS 1.1%CVE-2025-6586HIGHDownload Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File UploadEPSS 1.1%CVE-2021-33698CRITICALSAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the prEPSS 1.1%CVE-2021-39222MEDIUMXSS in TalkEPSS 1.1%CVE-2022-42229HIGHWedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.EPSS 1.1%CVE-2024-39397CRITICALAdobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 1.1%CVE-2024-10901CRITICALArbitrary File Write via DuckDB SQL Injection in eosphoros-ai/db-gptEPSS 1.1%CVE-2023-29657HIGHeXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbiEPSS 1.1%CVE-2025-6220HIGHUltimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'EPSS 1.1%CVE-2023-24720CRITICALAn arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.EPSS 1.1%CVE-2022-44048CRITICALThe d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code exEPSS 1.1%CVE-2022-43304CRITICALThe d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2022-44049CRITICALThe d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code EPSS 1.1%CVE-2022-44051CRITICALThe d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2022-43303CRITICALThe d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential codeEPSS 1.1%CVE-2022-43305CRITICALThe d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code EPSS 1.1%CVE-2024-4820MEDIUMSourceCodester Online Computer and Laptop Store unrestricted uploadEPSS 1.1%