Falhas do tipo CWE-434

3.087 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-39548—CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.7%CVE-2024-10993MEDIUMCodezips Online Institute Management System manage_website.php unrestricted uploadEPSS 0.7%CVE-2021-31314CRITICALFile upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the EPSS 0.7%CVE-2024-11984CRITICALSUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous TypeEPSS 0.7%CVE-2022-38140HIGHWordPress SEO Plugin by Squirrly SEO Plugin <= 12.1.10 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2022-23026—On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12EPSS 0.7%CVE-2026-3025MEDIUMShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted uploadEPSS 0.7%CVE-2024-0194MEDIUMCodeAstro Internet Banking System Profile Picture pages_account.php unrestricted uploadEPSS 0.7%CVE-2023-5034MEDIUMSourceCodester My Food Recipe Image Upload index.php unrestricted uploadEPSS 0.7%CVE-2025-4391CRITICALEcho RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2023-33498HIGHalist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.EPSS 0.7%CVE-2024-7620MEDIUMCustomizer Export/Import <= 0.9.7 - Authenticated (Admin+) Arbitrary File Upload via Customization Settings ImportEPSS 0.7%CVE-2025-22133CRITICALWeGIA Allows Arbitrary File Upload with Remote Code Execution (RCE)EPSS 0.7%CVE-2025-46616CRITICALQuantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNextEPSS 0.7%CVE-2025-4556CRITICALZONG YU Okcat Parking Management Platform - Arbitrary File UploadEPSS 0.7%CVE-2024-13342HIGHBooster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File UploadEPSS 0.7%CVE-2025-4279HIGHExternal image replace <= 1.0.8 - Authenticated (Contributor+) Arbitrary File UploadEPSS 0.7%CVE-2025-11456CRITICALELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2024-9038MEDIUMCodezips Online Shopping Portal insert-product.php unrestricted uploadEPSS 0.7%CVE-2025-12673CRITICALFlex QR Code Generator <= 1.2.7 - Unauthenticated Arbitrary File UploadEPSS 0.7%