Falhas do tipo CWE-434

3.083 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2024-9920MEDIUMUnrestricted File Upload and Execution in parisneo/lollms-webuiEPSS 1.4%CVE-2024-10578HIGHPubnews <= 1.0.7 - Authenticated (Subscriber+) Arbitrary Plugin InstallationEPSS 1.4%CVE-2026-14345CRITICALWPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' ParameterEPSS 1.4%CVE-2023-6220HIGHPiotnet Forms <= 1.0.28 - Unauthenticated Arbitrary File UploadEPSS 1.4%CVE-2024-52375CRITICALWordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerabilityEPSS 1.4%CVE-2024-11313CRITICALTRCore DVC - Arbitrary File Upload through Path TraversalEPSS 1.4%CVE-2024-11314CRITICALTRCore DVC - Arbitrary File Upload through Path TraversalEPSS 1.4%CVE-2024-11311CRITICALTRCore DVC - Arbitrary File Upload through Path TraversalEPSS 1.4%CVE-2024-11312CRITICALTRCore DVC - Arbitrary File Upload through Path TraversalEPSS 1.4%CVE-2024-11315CRITICALTRCore DVC - Arbitrary File Upload through Path TraversalEPSS 1.4%CVE-2024-34110HIGHRCE in the Adobe Commerce Webhook module through a legit webhook definitionEPSS 1.4%CVE-2025-5058CRITICALeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image()EPSS 1.4%CVE-2023-3375HIGHUnrestricted File Upload in BookreenEPSS 1.4%CVE-2023-1728CRITICALUnrestricted Upload of File with Dangerous Type in Fernus LMSEPSS 1.4%CVE-2022-48079CRITICALMonnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code viEPSS 1.4%CVE-2024-6132HIGHPexels: Free Stock Photos <= 1.2.2 - Authenticated (Contributor+) Arbitrary File UploadEPSS 1.4%CVE-2022-1519CRITICALLRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, includingEPSS 1.4%CVE-2024-3962CRITICALProduct Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_fileEPSS 1.4%CVE-2023-49715MEDIUMA unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fEPSS 1.4%CVE-2024-0864CRITICALRCE in LaragonEPSS 1.4%