Falhas do tipo CWE-434

3.080 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-40471CRITICALRemote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploaEPSS 21.8%CVE-2023-46474HIGHFile Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploEPSS 21.2%CVE-2023-5149MEDIUMD-Link DAR-7000 userattestation.php unrestricted uploadEPSS 21.0%CVE-2025-24801HIGHGLPI allows authenticated remote code executionEPSS 21.0%CVE-2023-28725CRITICALGeneral Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute aEPSS 20.6%CVE-2025-9712HIGHInsufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker toEPSS 20.5%CVE-2023-31689CRITICALIn Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parEPSS 20.2%CVE-2026-48939CRITICALJoomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15EPSS 20.1%KEVCVE-2023-34747CRITICALFile upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.EPSS 20.0%CVE-2025-1025HIGHVersions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extensioEPSS 18.9%CVE-2024-25869HIGHAn Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitraEPSS 18.7%CVE-2022-46610HIGH72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackerEPSS 18.1%CVE-2022-38916CRITICALA file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious filesEPSS 17.9%CVE-2024-22567HIGHFile Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.EPSS 17.8%CVE-2024-7855HIGHWP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 17.7%CVE-2024-31214CRITICALTraccar's unrestricted file upload vulnerability in device image upload could lead to remote code executionEPSS 17.6%CVE-2024-13171HIGHInsufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allowsEPSS 17.6%CVE-2024-22263HIGHArbitrary File Write Vulnerability in Spring Cloud Data FlowEPSS 17.5%CVE-2024-5008HIGHWhatsUp Gold APM Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 17.3%CVE-2024-7074MEDIUMAuthenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Service Leading to Remote Code ExecutionEPSS 17.2%