Falhas do tipo CWE-434

3.083 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-6558HIGHExport and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File UploadEPSS 1.4%CVE-2023-27178CRITICALAn arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted EPSS 1.4%CVE-2023-6576MEDIUMByzoro S210 HTTP POST Request uploadfile.php unrestricted uploadEPSS 1.4%CVE-2023-28353HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any locEPSS 1.4%CVE-2021-33352CRITICALAn issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar fEPSS 1.4%CVE-2009-20011CRITICALContentKeeper Web Appliance < 125.10 RCE via mimencodeEPSS 1.4%CVE-2024-27923HIGHRemote Code Execution by uploading a phar file using frontmatterEPSS 1.4%CVE-2022-23155HIGHDell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileEPSS 1.4%CVE-2024-32880CRITICALpyLoad allows upload to arbitrary folder lead to RCEEPSS 1.4%CVE-2024-31114CRITICALWordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerabilityEPSS 1.4%CVE-2024-28713CRITICALAn issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.EPSS 1.3%CVE-2024-11617CRITICALEnvolve Plugin <= 1.0 - Unauthenticated Arbitrary File Upload via language_file and fonts_fileEPSS 1.3%CVE-2025-55746CRITICALDirectus allows unauthenticated file upload and file modification due to lacking input sanitizationEPSS 1.3%CVE-2025-4336HIGHeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_file()EPSS 1.3%CVE-2022-41382CRITICALThe d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2022-42038CRITICALThe d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. TheEPSS 1.3%CVE-2012-10062HIGHXAMPP WebDAV PHP Upload Authentication Bypass RCEEPSS 1.3%CVE-2020-21489CRITICALFile Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2FupdEPSS 1.3%CVE-2020-20718CRITICALFile Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to tEPSS 1.3%CVE-2020-21174CRITICALFile Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.EPSS 1.3%