Falhas do tipo CWE-434

3.080 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-48148CRITICALWordPress StoreKeeper for WooCommerce Plugin <= 14.4.4 - Arbitrary File Upload VulnerabilityEPSS 16.7%CVE-2021-20022HIGHSonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to EPSS 16.5%KEVCVE-2024-44871HIGHAn arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via upEPSS 16.2%CVE-2025-3914HIGHAeropage Sync for Airtable <= 3.2.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 16.2%CVE-2021-39141HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 16.1%CVE-2024-24399HIGHAn arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code EPSS 15.6%CVE-2022-1103Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File UploadEPSS 15.6%CVE-2022-1565HIGHImport any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File UploadEPSS 15.4%CVE-2022-45275HIGHAn arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attEPSS 15.3%CVE-2018-17936NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files toEPSS 15.3%CVE-2023-41998CRITICALArcserve UDP Unauthenticated RCEEPSS 15.3%CVE-2021-21350MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 15.2%CVE-2025-34040CRITICALSeeyon Zhiyuan OA System Path Traversal File UploadEPSS 15.1%CVE-2026-48908CRITICALJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2EPSS 15.1%CVE-2025-34077CRITICALWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCEEPSS 15.1%CVE-2023-5154MEDIUMD-Link DAR-8000 changelogo.php unrestricted uploadEPSS 15.1%CVE-2024-10392CRITICALAI Power: Complete AI Pack <= 1.8.89 - Unauthenticated Arbitrary File UploadEPSS 15.0%CVE-2026-56291CRITICALJoomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1EPSS 14.9%KEVCVE-2026-30821HIGHFlowise: Arbitrary File Upload via MIME SpoofingEPSS 14.7%CVE-2023-4596CRITICALForminator <= 1.24.6 - Unauthenticated Arbitrary File UploadEPSS 14.3%