Falhas do tipo CWE-434

3.086 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-34007CRITICALWordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File UploadEPSS 0.9%CVE-2024-4560CRITICALKognetiks Chatbot for WordPress <= 1.9.9 - Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant FunctionEPSS 0.9%CVE-2024-6314CRITICALIQ Testimonials <= 2.2.7 - Unauthenticated Arbitrary File UploadEPSS 0.9%CVE-2024-13981CRITICALLiveBos UploadFile.do Arbitrary File UploadEPSS 0.9%CVE-2026-18438HIGHTemplately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename MismatchEPSS 0.9%CVE-2023-45603CRITICALWordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File UploadEPSS 0.9%CVE-2022-0962CRITICALStored XSS viva .webma file upload in star7th/showdocEPSS 0.9%CVE-2023-27033CRITICALPrestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrEPSS 0.9%CVE-2023-3804MEDIUMChengdu Flash Flood Disaster Monitoring and Warning System FileHandler.ashx unrestricted uploadEPSS 0.9%CVE-2024-48454HIGHAn issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=userEPSS 0.9%CVE-2025-66802CRITICALSourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (pEPSS 0.9%CVE-2023-42659CRITICALWS_FTP Server Arbitrary File UploadEPSS 0.9%CVE-2022-36452CRITICALA vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload maliEPSS 0.9%CVE-2019-25630HIGHPhreeBooks ERP 5.2.3 Arbitrary File Upload via Image ManagerEPSS 0.9%CVE-2024-13333HIGHAdvanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2024-35570CRITICALAn arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to executeEPSS 0.9%CVE-2023-1942MEDIUMSourceCodester Online Computer and Laptop Store Avatar unrestricted uploadEPSS 0.9%CVE-2019-25758HIGHJoomla! Component vBizz 1.0.7 Remote Code ExecutionEPSS 0.9%CVE-2024-13448CRITICALThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_dataEPSS 0.9%CVE-2023-3491HIGHUnrestricted Upload of File with Dangerous Type in fossbilling/fossbillingEPSS 0.9%