Falhas do tipo CWE-434

3.086 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-48394HIGHKaifa Technology WebITR - Arbitrary File UploadEPSS 0.9%CVE-2023-7091MEDIUMDreamer CMS uploadFile unrestricted uploadEPSS 0.9%CVE-2025-29017HIGHA Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in theEPSS 0.9%CVE-2022-0951HIGHFile Upload Restriction Bypass leading to Stored XSS Vulnerability in star7th/showdocEPSS 0.9%CVE-2025-55835CRITICALFile Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.EPSS 0.9%CVE-2023-2424MEDIUMDedeCMS config.php UpDateMemberModCache unrestricted uploadEPSS 0.9%CVE-2024-40125CRITICALAn arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execuEPSS 0.9%CVE-2023-4409MEDIUMNBS&HappySoftWeChat unrestricted uploadEPSS 0.9%CVE-2023-1501MEDIUMRockOA acloudCosAction.php.SQL runAction unrestricted uploadEPSS 0.9%CVE-2023-41506CRITICALAn arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackEPSS 0.9%CVE-2024-56828CRITICALFile Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoiEPSS 0.9%CVE-2024-36415CRITICALSuiteCRM Improper Control of Filename for Include Statement in PHP and Unrestricted Upload of File with Dangerous content leads to authenticated remote code executionEPSS 0.9%CVE-2026-33435HIGHWeblate: Remote code execution during backup restorationEPSS 0.9%CVE-2025-2006HIGHInline Image Upload for BBPress <= 1.1.19 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2025-9216HIGHStoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2025-26350MEDIUMA CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.1EPSS 0.9%CVE-2023-3797MEDIUMGen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System UploadFloodPlanFileUpdate.ashx unrestricted uploadEPSS 0.9%CVE-2023-0783MEDIUMEcShop PHP File template.php unrestricted uploadEPSS 0.9%CVE-2024-4966MEDIUMSourceCodester SchoolWebTech home.php unrestricted uploadEPSS 0.9%CVE-2024-56264MEDIUMWordPress ACF City Selector plugin <= 1.14.0 - Arbitrary File Upload vulnerabilityEPSS 0.9%