Falhas do tipo CWE-434

3.081 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2019-18288A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentiEPSS 4.0%CVE-2024-39717MEDIUMThe Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logEPSS 4.0%KEVCVE-2025-2749HIGHKentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCEEPSS 4.0%KEVCVE-2015-10135CRITICALWPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File UploadEPSS 4.0%CVE-2022-20743MEDIUMCisco Firepower Management Center File Upload Security Bypass VulnerabilityEPSS 4.0%CVE-2021-24220All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option DeletionEPSS 3.9%CVE-2021-22698A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 aEPSS 3.9%CVE-2023-3722HIGHAvaya Aura Device Services Remote Code ExecutionEPSS 3.9%CVE-2020-6008LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code executionEPSS 3.8%CVE-2026-38526CRITICALAn authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to eEPSS 3.8%CVE-2024-31777CRITICALFile Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.pEPSS 3.8%CVE-2018-11091CRITICALAn issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for anEPSS 3.7%CVE-2023-3049CRITICALFile Upload in TMT's LockcellEPSS 3.7%CVE-2021-24376Autoptimize < 2.7.8 - Arbitrary File Upload via "Import Settings"EPSS 3.7%CVE-2013-10040CRITICALClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCEEPSS 3.7%CVE-2026-14483CRITICALRealtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' CommandEPSS 3.6%CVE-2013-10032HIGHGetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File UploadEPSS 3.6%CVE-2023-2246MEDIUMSourceCodester Online Pizza Ordering System unrestricted uploadEPSS 3.6%CVE-2015-10138CRITICALWork The Flow File Upload <= 2.5.2 - Arbitrary File UploadEPSS 3.6%CVE-2023-4739MEDIUMByzoro Smart S85F Management Platform updateos.php unrestricted uploadEPSS 3.6%