Falhas do tipo CWE-434

3.081 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2015-10144HIGHResponsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 3.1%CVE-2021-24240Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCEEPSS 3.0%CVE-2024-36858CRITICALAn arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via EPSS 3.0%CVE-2021-40905HIGHThe web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" fileEPSS 3.0%CVE-2024-4963MEDIUMD-Link DAR-7000-40 url.php unrestricted uploadEPSS 3.0%CVE-2022-44289HIGHThinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.EPSS 3.0%CVE-2022-40797CRITICALRoxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .phEPSS 2.9%CVE-2020-26285HIGHWidget instances allows a hacker to inject an executable file on the server on OpenMageEPSS 2.9%CVE-2023-6274MEDIUMByzoro Smart S80 PHP File updatelib.php unrestricted uploadEPSS 2.9%CVE-2022-2128CRITICALUnrestricted Upload of File with Dangerous Type in polonel/trudeskEPSS 2.9%CVE-2020-15189MEDIUMRemote Code Execution in SOY CMSEPSS 2.8%CVE-2021-42133An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service tEPSS 2.8%CVE-2012-10054CRITICALUmbraco CMS < 4.7.1 codeEditorSave.asmx RCEEPSS 2.8%CVE-2019-18313A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 2.8%CVE-2021-38484CRITICALInHand Networks IR615 RouterEPSS 2.8%CVE-2026-84434CRITICALGravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload FieldEPSS 2.8%CVE-2025-23942CRITICALWordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerabilityEPSS 2.7%CVE-2024-23534HIGHAn Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to executEPSS 2.7%CVE-2017-6027An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web EPSS 2.6%CVE-2013-10034CRITICALKaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCEEPSS 2.6%