Falhas do tipo CWE-434

3.083 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2020-19802CRITICALFile Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameteEPSS 1.1%CVE-2023-25132CRITICALUnrestricted upload of file with dangerous type vulnerability in CyberPower PowerPanel BusinessEPSS 1.1%CVE-2024-5441HIGHModern Events Calendar <= 7.11.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.1%CVE-2024-33438HIGHFile Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.EPSS 1.1%CVE-2023-30185CRITICALCRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.pEPSS 1.1%CVE-2024-22060HIGHAn unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user tEPSS 1.1%CVE-2022-0263MEDIUMUnrestricted Upload of File with Dangerous Type in pimcore/pimcoreEPSS 1.1%CVE-2024-22641HIGHTCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.EPSS 1.1%CVE-2023-33569HIGHSourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.EPSS 1.1%CVE-2022-42034HIGHWedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.EPSS 1.1%CVE-2025-7847HIGHAI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.1%CVE-2021-3745HIGHUnrestricted Upload of File with Dangerous Type in flatcore/flatcore-cmsEPSS 1.1%CVE-2020-19028HIGH*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/pEPSS 1.1%CVE-2023-24269HIGHAn arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a EPSS 1.1%CVE-2022-45896CRITICALPlanet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. UploadEPSS 1.1%CVE-2022-44036HIGHIn b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to commEPSS 1.1%CVE-2024-6313CRITICALGutenberg Forms <= 2.2.9 - Unauthenticated Arbitrary File UploadEPSS 1.1%CVE-2022-24749MEDIUMBasic Cross-site Scripting and Unrestricted Upload of File with Dangerous Type in SyliusEPSS 1.1%CVE-2023-53922CRITICALTinyWebGallery v2.5 Remote Code Execution via Unrestricted File UploadEPSS 1.1%CVE-2023-51034HIGHTOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.EPSS 1.1%