Falhas do tipo CWE-434

3.066 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2026-15282CRITICALInstant Appointment <= 1.2 - Unauthenticated Arbitrary File UploadEPSS 1.1%CVE-2013-10055CRITICALHavalite CMS Arbitary File Upload RCEEPSS 1.1%CVE-2022-44054CRITICALThe d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code exeEPSS 1.1%CVE-2024-10901CRITICALArbitrary File Write via DuckDB SQL Injection in eosphoros-ai/db-gptEPSS 1.1%CVE-2019-6839A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6EPSS 1.1%CVE-2026-13352HIGHPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter ExpansionEPSS 1.1%CVE-2024-42676HIGHFile Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary codEPSS 1.1%CVE-2023-42017HIGHIBM Planning Analytics file uploadEPSS 1.1%CVE-2022-47769CRITICALAn arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious fileEPSS 1.1%CVE-2022-42971CRITICALA CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uplEPSS 1.1%CVE-2023-24646CRITICALAn arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitraEPSS 1.1%CVE-2022-44050CRITICALThe d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential cEPSS 1.1%CVE-2022-44052CRITICALThe d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code eEPSS 1.1%CVE-2020-23591CRITICALA vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary fEPSS 1.1%CVE-2022-44400CRITICALPurchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.EPSS 1.1%CVE-2024-7770HIGHBit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.1%CVE-2026-15158CRITICALBlocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' ParameterEPSS 1.1%CVE-2026-22786HIGHGin-vue-admin has arbitrary file upload vulnerability caused by path traversalEPSS 1.1%CVE-2024-50473CRITICALWordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerabilityEPSS 1.1%CVE-2024-50482CRITICALWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerabilityEPSS 1.1%