Falhas do tipo CWE-434

3.098 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-14842MEDIUMDrag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File UploadEPSS 0.4%CVE-2025-14199MEDIUMVerysync 微力同步 Web Administration text.txt unrestricted uploadEPSS 0.4%CVE-2026-0547MEDIUMPHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted uploadEPSS 0.4%CVE-2022-43192MEDIUMAn arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrEPSS 0.4%CVE-2026-1065HIGHForm Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG fileEPSS 0.4%CVE-2025-10371MEDIUMeCharge Hardy Barth Salia PLCC api.php unrestricted uploadEPSS 0.4%CVE-2025-10856HIGHArbitrary File Upload in Solvera Software's TeknoeraEPSS 0.4%CVE-2024-46482HIGHAn arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to EPSS 0.4%CVE-2024-42375MEDIUMMultiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence PlatformEPSS 0.4%CVE-2023-42248MEDIUMAn issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipEPSS 0.4%CVE-2026-24729CRITICALInterinfo DreamMaker - Unrestricted Upload of File with Dangerous TypeEPSS 0.4%CVE-2024-11404MEDIUMFile Upload Bypass in django FilerEPSS 0.4%CVE-2025-10615MEDIUMitsourcecode E-Commerce Website products.php unrestricted uploadEPSS 0.4%CVE-2025-13185MEDIUMBdtask/CodeCanyon News365 profile unrestricted uploadEPSS 0.4%CVE-2023-25365HIGHCross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3EPSS 0.4%CVE-2025-13411MEDIUMCampcodes Retro Basketball Shoes Online Store admin_football.php unrestricted uploadEPSS 0.4%CVE-2026-0566MEDIUMcode-projects Content Management System edit_posts.php unrestricted uploadEPSS 0.4%CVE-2025-8171MEDIUMcode-projects Document Management System insert.php unrestricted uploadEPSS 0.4%CVE-2024-11390MEDIUMKibana Unrestricted Upload of File with Dangerous Type Can Lead to XSSEPSS 0.4%CVE-2026-1813MEDIUMbolo-blog bolo-solo FreeMarker Template PicUploadProcessor.java unrestricted uploadEPSS 0.4%