Falhas do tipo CWE-434

3.099 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2024-45137HIGHInDesign Desktop | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 0.3%CVE-2024-45136HIGHInCopy | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 0.3%CVE-2025-49329MEDIUMWordPress Store Locator WordPress plugin <= 1.5.2 - Arbitrary File Upload VulnerabilityEPSS 0.3%CVE-2026-85134HIGHArbitrary File Upload Leading to Remote Command Execution in Bimser's eBA PlusEPSS 0.3%CVE-2026-23499HIGHSaleor vulnerable to stored XSS via Unrestricted File UploadEPSS 0.3%CVE-2025-60731HIGHPerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme functionEPSS 0.3%CVE-2025-60735HIGHPerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin functionEPSS 0.3%CVE-2026-22789MEDIUMWebErpMesv2 has a File Upload Validation Bypass Leading to RCEEPSS 0.3%CVE-2025-65416MEDIUMdocuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.EPSS 0.3%CVE-2025-62182MEDIUMPega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.EPSS 0.3%CVE-2025-64176MEDIUMThinkDashboard: Arbitrary File Upload vulnerability in the Backup Import FeatureEPSS 0.3%CVE-2026-54179MEDIUMbackpack/crud: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public diskEPSS 0.3%CVE-2025-12344MEDIUMYonyou U8 Cloud Request Header NCloudGatewayServlet unrestricted uploadEPSS 0.3%CVE-2025-10755MEDIUMSelleo Mentingo Content-Type unrestricted uploadEPSS 0.3%CVE-2025-10669MEDIUMAirsonic-Advanced Playlist Upload unrestricted uploadEPSS 0.3%CVE-2025-70849MEDIUMArbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /storEPSS 0.3%CVE-2025-13198MEDIUMDouPHP file.class.php unrestricted uploadEPSS 0.3%CVE-2024-42180LOWHCL MyXalytics is affected by a malicious file upload vulnerabilityEPSS 0.3%CVE-2024-1332MEDIUMCustom Fonts – Host Your Fonts Locally <= 2.1.4 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-1879MEDIUMHarvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted uploadEPSS 0.3%