Falhas do tipo CWE-434

3.086 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-46493CRITICALDefault version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.EPSS 0.8%CVE-2022-0945CRITICALStored XSS viva axd and cshtml file upload in star7th/showdoc in star7th/showdocEPSS 0.8%CVE-2026-81402CRITICALDS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File UploadEPSS 0.8%CVE-2024-42991HIGHMCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.EPSS 0.8%CVE-2023-29102CRITICALWordPress Olive One Click Demo Import Plugin <= 1.1.1 is vulnerable to Arbitrary File UploadEPSS 0.8%CVE-2020-19786HIGHFile upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP fiEPSS 0.8%CVE-2024-0185MEDIUMRRJ Nueva Ecija Engineer Online Portal Avatar dasboard_teacher.php unrestricted uploadEPSS 0.8%CVE-2022-47766HIGHPopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.EPSS 0.8%CVE-2026-72592CRITICALdulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File UploadEPSS 0.8%CVE-2024-3369MEDIUMcode-projects Car Rental add-vehicle.php unrestricted uploadEPSS 0.8%CVE-2024-6116MEDIUMitsourcecode Simple Online Hotel Reservation System edit_room.php unrestricted uploadEPSS 0.8%CVE-2024-6110MEDIUMitsourcecode Magbanua Beach Resort Online Reservation System controller.php unrestricted uploadEPSS 0.8%CVE-2024-6115MEDIUMitsourcecode Simple Online Hotel Reservation System add_room.php unrestricted uploadEPSS 0.8%CVE-2023-27246HIGHAn arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a cEPSS 0.8%CVE-2026-63223CRITICALCodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rulesEPSS 0.8%CVE-2024-33786CRITICALAn arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code viEPSS 0.8%CVE-2026-9102CRITICALPath Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File WriteEPSS 0.8%CVE-2019-25647HIGHPhreeBooks ERP 5.2.3 Remote Code Execution via Image ManagerEPSS 0.8%CVE-2023-34136—Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the EPSS 0.8%CVE-2026-55633HIGHDataEase H2 RCE via Zip Protocol & File Dropper Fix bypassEPSS 0.8%