Falhas do tipo CWE-434

3.082 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2021-32538CRITICALARTWARE CMS - Unrestricted Upload of FileEPSS 2.0%CVE-2023-46808CRITICALAn file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. SuccessEPSS 2.0%CVE-2023-27602CRITICALApache Linkis publicsercice module unrestricted upload of fileEPSS 2.0%CVE-2023-26852HIGHAn arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by upEPSS 2.0%CVE-2021-24493Shopp eCommerce <= 1.4 - Unauthenticated Arbitrary File UploadEPSS 2.0%CVE-2025-32028CRITICALHAX CMS PHP allows Insecure File Upload to Lead to Remote Code ExecutionEPSS 2.0%CVE-2013-10044HIGHOpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCEEPSS 2.0%CVE-2026-65640HIGHWordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. PrEPSS 1.9%CVE-2021-22803A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number ofEPSS 1.9%CVE-2020-3436HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services File Upload Denial of Service VulnerabilityEPSS 1.9%CVE-2023-33480HIGHRemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to EPSS 1.9%CVE-2024-34833CRITICALSourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unautheEPSS 1.9%CVE-2026-25099HIGHRemote Code Execution via Unrestricted File Upload in BluditEPSS 1.9%CVE-2021-24253Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCEEPSS 1.9%CVE-2021-24224Easy Form Builder <= 1.0 - Authenticated Arbitrary File UploadEPSS 1.9%CVE-2021-24171WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File UploadEPSS 1.9%CVE-2022-41705CRITICALBadaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because thEPSS 1.9%CVE-2020-11011CRITICALRCE via file upload in PhprojectEPSS 1.9%CVE-2023-51444HIGHGeoServer arbitrary file upload vulnerability in REST Coverage Store APIEPSS 1.9%CVE-2019-12803HIGHHunesion i-oneNet unrestricted file upload vulnerabilityEPSS 1.9%