Falhas do tipo CWE-434

3.083 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-47621HIGHRemote code execution via file uploads in guest-entries EPSS 1.0%CVE-2024-3912CRITICALASUS Router - Upload arbitrary firmwareEPSS 1.0%CVE-2024-4389HIGHSlider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File UploadEPSS 1.0%CVE-2022-2883HIGHIn affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of ServiceEPSS 1.0%CVE-2024-58282HIGHSerendipity 2.5.0 Remote Code Execution via Authenticated Media UploadEPSS 1.0%CVE-2022-42201HIGHSimple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.EPSS 1.0%CVE-2024-50510CRITICALWordPress AR For Woocommerce plugin <= 6.3 - Arbitrary File Upload vulnerabilityEPSS 1.0%CVE-2012-10056HIGHPHP Volunteer Management System 1.0.2 Arbitrary File UploadEPSS 1.0%CVE-2023-23328HIGHA File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploadiEPSS 1.0%CVE-2023-0670HIGHUlearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution onEPSS 1.0%CVE-2023-53933HIGHSerendipity 2.4.0 Authenticated Remote Code Execution via File UploadEPSS 1.0%CVE-2023-6976HIGHUnrestricted Upload of File with Dangerous TypeEPSS 1.0%CVE-2025-44658CRITICALIn Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .phpEPSS 1.0%CVE-2023-1970MEDIUMyuan1994 tpAdmin Upload.php Upload unrestricted uploadEPSS 1.0%CVE-2022-43234CRITICALAn arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted EPSS 1.0%CVE-2022-40050CRITICALZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.EPSS 1.0%CVE-2022-42154CRITICALAn arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary codEPSS 1.0%CVE-2025-11948CRITICALExcellent Infotek|Document Management System - Arbitrary File UploadEPSS 1.0%CVE-2023-3692MEDIUMUnrestricted Upload of File with Dangerous Type in admidio/admidioEPSS 1.0%CVE-2023-33386CRITICALMarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.EPSS 1.0%