Falhas do tipo CWE-434

3.083 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-48008CRITICALAn arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted EPSS 1.3%CVE-2023-6827HIGHEssential Real Estate <= 4.3.5 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.3%CVE-2024-56249CRITICALWordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerabilityEPSS 1.3%CVE-2020-20067HIGHFile upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.EPSS 1.3%CVE-2020-21325HIGHAn issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php fEPSS 1.3%CVE-2022-50939HIGHe107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File OverrideEPSS 1.3%CVE-2026-48283CRITICALColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 1.3%CVE-2026-48276CRITICALColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 1.3%CVE-2021-32961HIGHMDT AutoSave Unrestricted Upload of File with Dangerous TypeEPSS 1.3%CVE-2023-22726HIGHUnrestricted file upload leading to privilege escalation in actEPSS 1.3%CVE-2020-20919HIGHFile upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information viaEPSS 1.3%CVE-2023-35808HIGHAn issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been idenEPSS 1.3%CVE-2021-33009HIGHmySCADA myPRO Unrestricted Upload of File with Dangerous TypeEPSS 1.3%CVE-2022-0403Library File Manager < 5.2.3 - Subscriber+ Arbitrary File Creation/Upload/DeletionEPSS 1.3%CVE-2022-1837MEDIUMHome Clean Services Management System unrestricted uploadEPSS 1.3%CVE-2024-0783MEDIUMProject Worlds Online Admission System documents.php unrestricted uploadEPSS 1.2%CVE-2019-17325ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrlEPSS 1.2%CVE-2024-38529CRITICALAdmidio Vulnerable to RCE via Arbitrary File Upload in Message AttachmentEPSS 1.2%CVE-2022-39036CRITICALFLOWRING Agentflow BPM - Arbitrary File UploadEPSS 1.2%CVE-2012-10036CRITICALProject Pier <= 0.8.8 Arbitrary File Upload RCEEPSS 1.2%