Fallos del tipo CWE-434

3091 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2023-29635CRITICALFile upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to functiEPSS 1.1%CVE-2020-20735CRITICALFile Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.EPSS 1.1%CVE-2023-39970—Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.0EPSS 1.1%CVE-2023-39346HIGHbjrjk/LinuxASMCallGraph before commit 20dba06 allows attackers to cause a RCE on the server side via uploading a crafted ZIP file due to incorrect filtering rules of uploaded fileEPSS 1.1%CVE-2022-43306HIGHThe d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2026-6933HIGHPremmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin CreationEPSS 1.1%CVE-2022-45476CRITICALTiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for downloadEPSS 1.1%CVE-2022-41533HIGHOnline Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/EPSS 1.0%CVE-2024-43249CRITICALWordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2023-4186MEDIUMSourceCodester Pharmacy Management System manage_website.php unrestricted uploadEPSS 1.0%CVE-2023-22851HIGHTiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.EPSS 1.0%CVE-2024-49607CRITICALWordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2022-42198HIGHIn Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.EPSS 1.0%CVE-2024-2690MEDIUMSourceCodester Online Discussion Forum Site uupdate.php unrestricted uploadEPSS 1.0%CVE-2026-18351CRITICALDrag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' ParameterEPSS 1.0%CVE-2022-32177CRITICALGin-vue-admin - Unrestricted File UploadEPSS 1.0%CVE-2022-32176CRITICALGin-vue-admin - Unrestricted File UploadEPSS 1.0%CVE-2022-42201HIGHSimple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.EPSS 1.0%CVE-2023-5965MEDIUMUnrestricted Upload of File with Dangerous Type in EspoCRMEPSS 1.0%CVE-2023-5966MEDIUMUnrestricted Upload of File with Dangerous Type in EspoCRMEPSS 1.0%