Falhas do tipo CWE-434

3.087 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2024-13882HIGHAiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File UploadEPSS 0.8%CVE-2024-6801MEDIUMSourceCodester Online Student Management System add-students.php unrestricted uploadEPSS 0.8%CVE-2024-32254HIGHPhpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php.EPSS 0.8%CVE-2024-56046CRITICALWordPress WPLMS plugin <= 1.9.9 - Unauthenticated Arbitrary File Upload vulnerabilityEPSS 0.8%CVE-2022-4665LOWUnrestricted Upload of File with Dangerous Type in ampache/ampacheEPSS 0.8%CVE-2025-2216MEDIUMzzskzy Warehouse Refinement Management System SaveCrash.ashx UploadCrash unrestricted uploadEPSS 0.8%CVE-2023-29386CRITICALWordPress Manager for Icomoon plugin <= 2.0 - Arbitrary File Upload vulnerabilityEPSS 0.8%CVE-2024-6114MEDIUMitsourcecode Monbela Tourist Inn Online Reservation System controller.php unrestricted uploadEPSS 0.8%CVE-2023-27440HIGHWordPress Toolset Types plugin <= 3.4.17 - Authenticated Arbitrary File Upload VulnerabilityEPSS 0.8%CVE-2023-31090CRITICALWordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerabilityEPSS 0.8%CVE-2022-3575CRITICALFrauscher Sensortechnik Diagnostic System FDS102 for FAdC R2 and FAdCi R2 configuration upload vulnerabilityEPSS 0.8%CVE-2020-8974CRITICALZGR TPS200 NG Missing Reference to Active Allocated ResourceEPSS 0.8%CVE-2024-8296MEDIUMFeehiCMS index.php insert unrestricted uploadEPSS 0.8%CVE-2023-0651MEDIUMFastCMS Template Management unrestricted uploadEPSS 0.8%CVE-2024-8294MEDIUMFeehiCMS index.php update unrestricted uploadEPSS 0.8%CVE-2025-2249HIGHSoJ Soundslides <= 1.2.2 - Authenticated (Contributor+) Arbitrary File UploadEPSS 0.8%CVE-2024-8295MEDIUMFeehiCMS index.php createBanner unrestricted uploadEPSS 0.8%CVE-2026-33704HIGHChamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpointEPSS 0.8%CVE-2025-58159CRITICALWeGIA Authenticated Arbitrary File Upload Leading To Remote Code Execution (RCE)EPSS 0.8%CVE-2024-48781CRITICALAn issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a speciallEPSS 0.8%