Falhas do tipo CWE-434

3.082 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2021-24223N5 Upload Form <= 1.0 - Unauthenticated Arbitrary File Upload to RCEEPSS 2.2%CVE-2025-34111CRITICALTiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCEEPSS 2.2%CVE-2022-4949HIGHAdSanity < 1.8.2 - Authenticated Arbitrary File UploadEPSS 2.2%CVE-2019-1010209GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload EPSS 2.1%CVE-2025-4403CRITICALDrag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload FunctionEPSS 2.1%CVE-2026-27636HIGHFreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on ApacheEPSS 2.1%CVE-2023-24610HIGHNOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks EPSS 2.1%CVE-2022-28700CRITICALWordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerabilityEPSS 2.1%CVE-2022-34965HIGHOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /EPSS 2.1%CVE-2021-34623CRITICALProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader ComponentEPSS 2.1%CVE-2023-31903CRITICALGuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.EPSS 2.1%CVE-2025-15503MEDIUMSangfor Operation and Maintenance Management System common.jsp unrestricted uploadEPSS 2.1%CVE-2022-24387CRITICALFile upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010EPSS 2.1%CVE-2020-26252HIGHLayout XML RCE Vulnerability in OpenMageEPSS 2.1%CVE-2021-44164CRITICALChain Sea Information Integration Co., Ltd ai chatbot system - Arbitrary File UploadEPSS 2.1%CVE-2023-32526Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary fileEPSS 2.0%CVE-2023-32525Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary fileEPSS 2.0%CVE-2015-1784In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weEPSS 2.0%CVE-2023-29930HIGHAn issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via EPSS 2.0%CVE-2021-32538CRITICALARTWARE CMS - Unrestricted Upload of FileEPSS 2.0%