Falhas do tipo CWE-434

3.086 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-2738MEDIUMTongda OA GatewayController.php actionGetdata unrestricted uploadEPSS 0.9%CVE-2025-46157CRITICALAn issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave requesEPSS 0.9%CVE-2020-37084HIGHSchool ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-1328MEDIUMGuizhou 115cms index unrestricted uploadEPSS 0.9%CVE-2021-34076HIGHFile Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file EPSS 0.9%CVE-2021-47757HIGHChikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)EPSS 0.9%CVE-2024-12853HIGHModula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File UploadEPSS 0.9%CVE-2022-43436HIGHHWA JIUH DIGITAL TECHNOLOGY LTD. EasyTest - Arbitrary File UploadEPSS 0.9%CVE-2026-37748HIGHVisitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.EPSS 0.9%CVE-2023-28699HIGHWADE DIGITAL DESIGN CO, LTD. FANTSY - Arbitrary File UploadEPSS 0.9%CVE-2024-31286CRITICALWordPress WP Photo Album Plus plugin < 8.6.03.005 - Arbitrary File Upload vulnerabilityEPSS 0.9%CVE-2026-49827CRITICALWebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)EPSS 0.9%CVE-2023-1744MEDIUMIBOS htaccess unrestricted uploadEPSS 0.9%CVE-2025-10647HIGHEmbed PDF for WPForms <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2023-50922HIGHAn issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code bEPSS 0.9%CVE-2022-44401CRITICALOnline Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.EPSS 0.9%CVE-2026-88738HIGHJazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attaEPSS 0.9%CVE-2015-0796MEDIUMopen build service source server symlink exploitation via source patchEPSS 0.9%CVE-2020-22539HIGHAn arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadiEPSS 0.9%CVE-2024-8615CRITICALWP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File UploadEPSS 0.9%