Fallos del tipo CWE-434

3084 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2023-25655CRITICALbaserCMS allows any file to be uploadedEPSS 1.1%CVE-2024-37868HIGHFile Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "EPSS 1.1%CVE-2024-37869HIGHFile Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "EPSS 1.1%CVE-2025-1980HIGHRemote Code Execution via Unrestricted File Upload in Ready_EPSS 1.1%CVE-2022-40932HIGHIn Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "GalEPSS 1.1%CVE-2026-49972HIGHLaravel-Mediable < 7.0.0 File Upload RCE via Extension BypassEPSS 1.1%CVE-2025-0357CRITICALWPBookit <= 1.6.9 - Unauthenticated Arbitrary File UploadEPSS 1.1%CVE-2022-45009HIGHOnline Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettingsEPSS 1.1%CVE-2022-45039HIGHAn arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a craEPSS 1.1%CVE-2026-15282CRITICALInstant Appointment <= 1.2 - Unauthenticated Arbitrary File UploadEPSS 1.1%CVE-2022-44054CRITICALThe d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code exeEPSS 1.1%CVE-2026-13352HIGHPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter ExpansionEPSS 1.1%CVE-2019-6839—A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6EPSS 1.1%CVE-2024-42676HIGHFile Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary codEPSS 1.1%CVE-2023-42017HIGHIBM Planning Analytics file uploadEPSS 1.1%CVE-2022-47769CRITICALAn arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious fileEPSS 1.1%CVE-2022-44050CRITICALThe d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential cEPSS 1.1%CVE-2022-42971CRITICALA CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uplEPSS 1.1%CVE-2022-44052CRITICALThe d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2023-24646CRITICALAn arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitraEPSS 1.1%