Falhas do tipo CWE-434

3.096 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-46080MEDIUMHuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files EPSS 0.4%CVE-2026-71434MEDIUMStatamic: Missing file upload validation on frontend forms allows uploading disallowed file typesEPSS 0.4%CVE-2025-10427MEDIUMSourceCodester Pet Grooming Management Software user.php unrestricted uploadEPSS 0.4%CVE-2026-81236HIGHDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unaEPSS 0.4%CVE-2025-15360MEDIUMnewbee-mall-plus Product Information Edit UploadController.java upload unrestricted uploadEPSS 0.4%CVE-2019-25673HIGHUniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File UploadEPSS 0.4%CVE-2025-10428MEDIUMSourceCodester Pet Grooming Management Software Setting seo_setting.php unrestricted uploadEPSS 0.4%CVE-2024-47528MEDIUMLibreNMS Contains a Stored XSS via File UploadEPSS 0.4%CVE-2026-15553MEDIUMRagic|Enterprise Cloud Database - Arbitrary File UploadEPSS 0.4%CVE-2026-60032CRITICALJoomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0EPSS 0.4%CVE-2025-59835HIGHLangBot has a cross-directory file upload vulnerability, which could lead to system takeoverEPSS 0.4%CVE-2025-5108MEDIUMzongzhige ShopXO ZIP File Payment.php Upload unrestricted uploadEPSS 0.4%CVE-2025-4735MEDIUMCampcodes Sales and Inventory System product.php unrestricted uploadEPSS 0.4%CVE-2026-33273MEDIUMUnrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbEPSS 0.4%CVE-2025-4291MEDIUMIdeaCMS saveUpload unrestricted uploadEPSS 0.4%CVE-2025-57176MEDIUMOn Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP poEPSS 0.4%CVE-2025-9296MEDIUMEmlog Pro blogger.php unrestricted uploadEPSS 0.4%CVE-2025-63748HIGHQaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The applicatEPSS 0.4%CVE-2026-65986HIGHCVAT has stored XSS via annotation guide assetsEPSS 0.4%CVE-2025-9847MEDIUMScriptAndTools Real Estate Management System register.php unrestricted uploadEPSS 0.4%