Falhas do tipo CWE-434

3.084 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-2212MEDIUMSourceCodester Library Management System /card/index.php unrestricted uploadEPSS 1.0%CVE-2025-4389CRITICALCrawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File UploadEPSS 1.0%CVE-2024-6707HIGHOpen WebUI Arbitrary File Upload + Path TraversalEPSS 1.0%CVE-2026-48356CRITICALAdobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 1.0%CVE-2024-7257CRITICALYayExtra – WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via handle_upload_file FunctionEPSS 1.0%CVE-2024-24202CRITICALAn arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 alEPSS 1.0%CVE-2024-58298CRITICALCompuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File UploadEPSS 1.0%CVE-2022-30529HIGHFile upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitraryEPSS 1.0%CVE-2026-23697HIGHVtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents ModuleEPSS 1.0%CVE-2025-1093CRITICALAIHub <= 1.3.7 - Unauthenticated Arbitrary File Upload in generate_imageEPSS 1.0%CVE-2026-2354HIGHSwiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()EPSS 1.0%CVE-2024-0916CRITICALUnauthenticated Remote Code Execution in UvDesk CommunityEPSS 1.0%CVE-2022-1345CRITICALStored XSS viva .svg file upload in causefx/organizrEPSS 1.0%CVE-2025-43946CRITICALTCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).EPSS 1.0%CVE-2022-44053CRITICALThe d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential cEPSS 1.0%CVE-2025-11499CRITICALTablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File UploadEPSS 1.0%CVE-2023-4159CRITICALUnrestricted Upload of File with Dangerous Type in omeka/omeka-sEPSS 1.0%CVE-2025-11391CRITICALPPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File UploadEPSS 1.0%CVE-2012-10042HIGHSflog! CMS 1.0 Arbitrary File Upload RCEEPSS 1.0%CVE-2022-43074CRITICALAyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerabiliEPSS 1.0%