Falhas do tipo CWE-434

3.099 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2024-10584MEDIUMDirectoryPress <= 3.6.16 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-25801MEDIUMSKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not tEPSS 0.3%CVE-2026-1969MEDIUMThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File UploadEPSS 0.3%CVE-2025-33023MEDIUMA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (AllEPSS 0.3%CVE-2024-36987MEDIUMInsecure File Upload in the indexing/preview REST endpointEPSS 0.3%CVE-2026-14906MEDIUMMalicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOSEPSS 0.3%CVE-2025-59525HIGHHorilla has Improper Input Sanitization Leading to XSS and Admin Account TakeoverEPSS 0.3%CVE-2025-24505HIGHThis vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploadiEPSS 0.3%CVE-2024-50652MEDIUMA file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.EPSS 0.3%CVE-2026-11474MEDIUMKushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadEPSS 0.3%CVE-2025-40678MEDIUMUnrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del EmpleadoEPSS 0.3%CVE-2022-27562MEDIUMHCL Domino Volt is affected by an unrestricted upload of a dangerous file typeEPSS 0.3%CVE-2022-44760MEDIUMHCL Leap is affected by an unrestricted upload of file with dangerous type vulnerabilityEPSS 0.3%CVE-2022-42449MEDIUMHCL Domino Volt is affected by an unrestricted upload of a dangerous file typeEPSS 0.3%CVE-2026-56590MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.3%CVE-2025-55383HIGHMoss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to EPSS 0.3%CVE-2025-55455LOWDooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.EPSS 0.3%CVE-2026-48946MEDIUMJoomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26EPSS 0.3%CVE-2024-25020MEDIUMIBM Cognos Controller file uploadEPSS 0.3%CVE-2024-25019MEDIUMIBM Cognos Controller file uploadEPSS 0.3%