Falhas do tipo CWE-434

3.091 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2024-10764MEDIUMCodezips Online Institute Management System save_user.php unrestricted uploadEPSS 0.5%CVE-2024-48646HIGHAn Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validatioEPSS 0.5%CVE-2025-7879MEDIUMMetasoft 美特软件 MetaCRM mobileupload.jsp unrestricted uploadEPSS 0.5%CVE-2025-7877MEDIUMMetasoft 美特软件 MetaCRM sendfile.jsp unrestricted uploadEPSS 0.5%CVE-2023-7305CRITICALSmartBI RMIServlet Unrestricted File Upload RCEEPSS 0.5%CVE-2024-45398HIGHRemote command execution through file upload in contao/core-bundleEPSS 0.5%CVE-2026-86239MEDIUMliufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted uploadEPSS 0.5%CVE-2025-9775MEDIUMRemoteClinic edit-my-profile.php unrestricted uploadEPSS 0.5%CVE-2025-8255MEDIUMcode-projects Exam Form Submission register.php unrestricted uploadEPSS 0.5%CVE-2025-9772MEDIUMRemoteClinic edit.php unrestricted uploadEPSS 0.5%CVE-2025-11347MEDIUMcode-projects Student Crud Operation Add Student Page/Edit Student add.php move_uploaded_file unrestricted uploadEPSS 0.5%CVE-2026-36467HIGHUnrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access EPSS 0.5%CVE-2023-30791HIGHPlane 0.7.1 - Insecure file uploadEPSS 0.5%CVE-2024-43243CRITICALWordPress JobBoard Job listing plugin <= 1.2.6 - Arbitrary File Upload vulnerabilityEPSS 0.5%CVE-2025-60500HIGHQDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictiEPSS 0.5%CVE-2026-38751HIGHOpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornaEPSS 0.5%CVE-2025-6206HIGHAiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.5%CVE-2025-1166MEDIUMSourceCodester Food Menu Manager update.php unrestricted uploadEPSS 0.5%CVE-2026-42322CRITICALPiwigo: Authenticated RCE via File Upload in Logo Upload FeatureEPSS 0.5%CVE-2026-1107MEDIUMEyouCMS Member Avatar Diyajax.php check_userinfo unrestricted uploadEPSS 0.5%