Falhas do tipo CWE-434

3.099 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-34854MEDIUMHotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.EPSS 0.2%CVE-2021-35485HIGHThe Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload sEPSS 0.2%CVE-2026-53948MEDIUMGhost: File Upload Content-Type SpoofingEPSS 0.2%CVE-2026-75331MEDIUMtamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadControllEPSS 0.2%CVE-2023-39538HIGHFailure when uploading a Logo image fileEPSS 0.2%CVE-2025-1725MEDIUMBit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File UploadsEPSS 0.2%CVE-2024-35593MEDIUMAn arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arbitrary code via uploEPSS 0.2%CVE-2026-11621MEDIUMDcat-Admin User Setting upload editorMDUpload unrestricted uploadEPSS 0.2%CVE-2026-0496MEDIUMMultiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)EPSS 0.2%CVE-2018-25168MEDIUMPrecurio Intranet Portal 2.0 Cross-Site Request Forgery Add AdminEPSS 0.2%CVE-2025-54757MEDIUMMultiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded byEPSS 0.2%CVE-2025-32215MEDIUMWordPress Accessibility Suite plugin <= 4.18 - Arbitrary File Upload vulnerabilityEPSS 0.2%CVE-2026-23704MEDIUMA non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be exEPSS 0.2%CVE-2026-11333MEDIUMtittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted uploadEPSS 0.2%CVE-2023-26098HIGHAn issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbEPSS 0.2%CVE-2025-31979MEDIUMA File Upload Validation Bypass vulnerability has been identified in the HCL BigFix Service Management (SM)EPSS 0.2%CVE-2025-60187MEDIUMWordPress Atarim plugin <= 4.2.1 - Arbitrary File Upload vulnerabilityEPSS 0.2%CVE-2025-2819MEDIUMUnrestricted FileuploadEPSS 0.2%CVE-2024-41340HIGHAn issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862EPSS 0.2%CVE-2025-55251LOWHCL AION is affected by an Unrestricted File Upload vulnerabilityEPSS 0.2%