Falhas do tipo CWE-434

3.087 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-22470CRITICALCL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. AnEPSS 0.7%CVE-2022-46102CRITICALAyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.phpEPSS 0.7%CVE-2022-45966CRITICALhere is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.EPSS 0.7%CVE-2026-16985HIGHSqueeze < 1.7.12 - Author+ Arbitrary File UploadEPSS 0.7%CVE-2020-37117HIGHjizhiCMS 1.6.7 - Arbitrary File DownloadEPSS 0.7%CVE-2026-77018HIGHWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass AssignmentEPSS 0.7%CVE-2026-76552HIGHWP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image ImportEPSS 0.7%CVE-2024-42777CRITICALAn Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which alloEPSS 0.7%CVE-2025-32579CRITICALWordPress Sync Posts Plugin <= 1.0 - Arbitrary File Upload vulnerabilityEPSS 0.7%CVE-2024-35510CRITICALAn arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uEPSS 0.7%CVE-2024-25994MEDIUMPHOENIX CONTACT: Unintended script file upload in CHARX SeriesEPSS 0.7%CVE-2026-22799CRITICALemlog Arbitrary File Upload VulnerabilityEPSS 0.7%CVE-2024-32256HIGHPhpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. EPSS 0.7%CVE-2023-1558MEDIUMSimple and Beautiful Shopping Cart System uploadera.php unrestricted uploadEPSS 0.7%CVE-2023-1739MEDIUMSourceCodester Simple and Beautiful Shopping Cart System upload.php unrestricted uploadEPSS 0.7%CVE-2025-2891HIGHWP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File UploadEPSS 0.7%CVE-2025-13329CRITICALFile Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-dataEPSS 0.7%CVE-2025-0731MEDIUMSMA: Sunny Portal Remote Code ExecutionEPSS 0.7%CVE-2026-81240HIGHDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unaEPSS 0.7%CVE-2026-81239HIGHDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unaEPSS 0.7%