Falhas do tipo CWE-434

3.065 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-42229HIGHWedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.EPSS 1.1%CVE-2021-39222MEDIUMXSS in TalkEPSS 1.1%CVE-2024-39397CRITICALAdobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 1.1%CVE-2023-29657HIGHeXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbiEPSS 1.1%CVE-2022-44049CRITICALThe d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code EPSS 1.1%CVE-2022-44048CRITICALThe d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code exEPSS 1.1%CVE-2022-43304CRITICALThe d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2022-43305CRITICALThe d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code EPSS 1.1%CVE-2022-44051CRITICALThe d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2023-24720CRITICALAn arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.EPSS 1.1%CVE-2022-43303CRITICALThe d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential codeEPSS 1.1%CVE-2024-4820MEDIUMSourceCodester Online Computer and Laptop Store unrestricted uploadEPSS 1.1%CVE-2023-25655CRITICALbaserCMS allows any file to be uploadedEPSS 1.1%CVE-2025-1980HIGHRemote Code Execution via Unrestricted File Upload in Ready_EPSS 1.1%CVE-2024-37868HIGHFile Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "EPSS 1.1%CVE-2024-37869HIGHFile Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "EPSS 1.1%CVE-2026-49972HIGHLaravel-Mediable < 7.0.0 File Upload RCE via Extension BypassEPSS 1.1%CVE-2025-0357CRITICALWPBookit <= 1.6.9 - Unauthenticated Arbitrary File UploadEPSS 1.1%CVE-2013-10055CRITICALHavalite CMS Arbitary File Upload RCEEPSS 1.1%CVE-2022-45009HIGHOnline Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettingsEPSS 1.1%