Falhas do tipo CWE-434

3.080 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2021-21347MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 14.3%CVE-2021-39146HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 14.3%CVE-2024-55417MEDIUMDevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /aEPSS 14.1%CVE-2025-40599CRITICALAn authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrEPSS 14.0%CVE-2025-9872HIGHInsufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker toEPSS 13.5%CVE-2022-45359CRITICALWordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File UploadEPSS 13.5%CVE-2025-13065HIGHStarter Templates <= 4.4.41 - Authenticated (Author+) Arbitrary File Upload via WXR Upload BypassEPSS 13.5%CVE-2024-8232HIGHiniNet Solutions SpiderControl SCADA Web Server Unrestricted Upload of File with Dangerous TypeEPSS 13.1%CVE-2013-1916In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on thEPSS 12.8%CVE-2024-25832HIGHF-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of danEPSS 12.8%CVE-2022-2419HIGHURVE Web Manager upload.php unrestricted uploadEPSS 12.8%CVE-2023-38098HIGHNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 12.7%CVE-2025-53119HIGHSecurden Unified PAM Unauthenticated Unrestricted File UploadEPSS 12.3%CVE-2025-61687HIGHFlowiseAI/Flosise has File Upload vulnerabilityEPSS 11.1%CVE-2021-43258HIGHCartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated accEPSS 11.0%CVE-2020-15645HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. AlthougEPSS 10.7%CVE-2025-61808CRITICALColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 10.6%CVE-2024-6127CRITICALBC Security Empire Path Traversal RCEEPSS 10.3%CVE-2025-54441HIGHUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affEPSS 10.3%CVE-2020-8866MEDIUMThis vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. AuEPSS 9.6%