Fallos del tipo CWE-434

3095 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2024-10993MEDIUMCodezips Online Institute Management System manage_website.php unrestricted uploadEPSS 0.7%CVE-2021-31314CRITICALFile upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the EPSS 0.7%CVE-2022-38140HIGHWordPress SEO Plugin by Squirrly SEO Plugin <= 12.1.10 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2022-23026—On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12EPSS 0.7%CVE-2026-3025MEDIUMShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted uploadEPSS 0.7%CVE-2024-0194MEDIUMCodeAstro Internet Banking System Profile Picture pages_account.php unrestricted uploadEPSS 0.7%CVE-2023-5034MEDIUMSourceCodester My Food Recipe Image Upload index.php unrestricted uploadEPSS 0.7%CVE-2025-4391CRITICALEcho RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2023-33498HIGHalist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.EPSS 0.7%CVE-2024-7620MEDIUMCustomizer Export/Import <= 0.9.7 - Authenticated (Admin+) Arbitrary File Upload via Customization Settings ImportEPSS 0.7%CVE-2025-22133CRITICALWeGIA Allows Arbitrary File Upload with Remote Code Execution (RCE)EPSS 0.7%CVE-2025-46616CRITICALQuantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNextEPSS 0.7%CVE-2026-1400HIGHAI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata EndpointEPSS 0.7%CVE-2024-13342HIGHBooster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File UploadEPSS 0.7%CVE-2025-4556CRITICALZONG YU Okcat Parking Management Platform - Arbitrary File UploadEPSS 0.7%CVE-2025-4279HIGHExternal image replace <= 1.0.8 - Authenticated (Contributor+) Arbitrary File UploadEPSS 0.7%CVE-2025-11456CRITICALELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2024-9038MEDIUMCodezips Online Shopping Portal insert-product.php unrestricted uploadEPSS 0.7%CVE-2025-12673CRITICALFlex QR Code Generator <= 1.2.7 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2025-22470CRITICALCL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. AnEPSS 0.7%