Falhas do tipo CWE-434

3.087 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2024-24551HIGHBludit - Remote Code Execution (RCE) through Image APIEPSS 0.8%CVE-2024-48781CRITICALAn issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a speciallEPSS 0.8%CVE-2025-58745CRITICALWeGIA has a bypass for the fix for CVE-2025-22133 - Arbitrary File Upload leads to Remote Code Execution (RCE)EPSS 0.8%CVE-2025-13646HIGHModula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race ConditionEPSS 0.8%CVE-2022-1811CRITICALUnrestricted Upload of File with Dangerous Type in publify/publifyEPSS 0.8%CVE-2022-45171HIGHAn issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under EPSS 0.8%CVE-2025-65897HIGHzdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation oEPSS 0.8%CVE-2023-24045MEDIUMIn Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target usernEPSS 0.8%CVE-2024-5518MEDIUMitsourcecode Online Discussion Forum change_profile_picture.php unrestricted uploadEPSS 0.8%CVE-2024-1008MEDIUMSourceCodester Employee Management System Profile Page edit-photo.php unrestricted uploadEPSS 0.8%CVE-2024-56897CRITICALImproper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commanEPSS 0.7%CVE-2024-24146MEDIUMA memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF fiEPSS 0.7%CVE-2023-1185MEDIUMECshop New Product unrestricted uploadEPSS 0.7%CVE-2023-1184MEDIUMECshop Backup Database database.php unrestricted uploadEPSS 0.7%CVE-2025-5395HIGHWordPress Automatic Plugin - AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File UploadEPSS 0.7%CVE-2014-125104MEDIUMVaultPress Plugin MailPoet Plugin class.vaultpress-hotfixes.php protect_aioseo_ajax unrestricted uploadEPSS 0.7%CVE-2024-51743HIGHArbitrary File Write leading up to remote code execution (instructor accounts)EPSS 0.7%CVE-2023-39548—CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.7%CVE-2023-30264CRITICALCLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.EPSS 0.7%CVE-2025-46612HIGHThe Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/worEPSS 0.7%