Falhas do tipo CWE-434

3.083 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-40407HIGHA zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.EPSS 1.3%CVE-2023-3295HIGHUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File UploadEPSS 1.3%CVE-2022-45802CRITICALApache StreamPark (incubating): Upload any file to any directoryEPSS 1.3%CVE-2012-10044CRITICALMobileCartly 1.0 savepage.php Arbitrary File CreationEPSS 1.3%CVE-2012-10050CRITICALCuteFlow <= 2.11.2 Arbitrary File Upload RCEEPSS 1.3%CVE-2012-10027CRITICALWordPress Plugin WP-Property <= 1.35.0 PHP File UploadEPSS 1.3%CVE-2020-36897CRITICALQiHang Media Web Digital Signage 3.0.9 Unauthenticated Remote Code ExecutionEPSS 1.3%CVE-2019-10935A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.EPSS 1.3%CVE-2021-28998HIGHFile upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar fileEPSS 1.3%CVE-2023-2712CRITICALMalicious File Upload vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform.EPSS 1.3%CVE-2024-53345HIGHAn authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary codeEPSS 1.3%CVE-2022-50898HIGHNanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated)EPSS 1.3%CVE-2021-27489ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file couEPSS 1.3%CVE-2022-41385CRITICALThe d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2021-26634CRITICALMaxboard multiple vulnerabilitiesEPSS 1.3%CVE-2022-42037CRITICALThe d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2022-41384CRITICALThe d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backEPSS 1.3%CVE-2022-41386CRITICALThe d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backEPSS 1.3%CVE-2022-41387CRITICALThe d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2022-41383CRITICALThe d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The bacEPSS 1.3%