Fallos del tipo CWE-434

3089 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2024-44871HIGHAn arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via upEPSS 16.2%CVE-2025-3914HIGHAeropage Sync for Airtable <= 3.2.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 16.2%CVE-2021-39141HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 16.1%CVE-2024-24399HIGHAn arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code EPSS 15.6%CVE-2022-1103—Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File UploadEPSS 15.6%CVE-2025-34040CRITICALSeeyon Zhiyuan OA System Path Traversal File UploadEPSS 15.4%CVE-2022-1565HIGHImport any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File UploadEPSS 15.4%CVE-2022-45275HIGHAn arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attEPSS 15.3%CVE-2018-17936—NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files toEPSS 15.3%CVE-2023-5154MEDIUMD-Link DAR-8000 changelogo.php unrestricted uploadEPSS 15.3%CVE-2023-41998CRITICALArcserve UDP Unauthenticated RCEEPSS 15.3%CVE-2021-21350MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 15.2%CVE-2025-34077CRITICALWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCEEPSS 15.1%CVE-2024-10392CRITICALAI Power: Complete AI Pack <= 1.8.89 - Unauthenticated Arbitrary File UploadEPSS 15.0%CVE-2026-56291CRITICALJoomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1EPSS 14.9%KEVCVE-2023-4596CRITICALForminator <= 1.24.6 - Unauthenticated Arbitrary File UploadEPSS 14.3%CVE-2021-21347MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 14.3%CVE-2021-39146HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 14.3%CVE-2024-55417MEDIUMDevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /aEPSS 14.1%CVE-2025-40599CRITICALAn authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrEPSS 14.0%