Falhas do tipo CWE-434

3.091 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-9515HIGHMulti Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File UploadEPSS 0.7%CVE-2020-6288MEDIUMSAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to uploadEPSS 0.7%CVE-2024-25636HIGHLack of media type verification of Activity Streams objects allows impersonation and takeover of remote accountsEPSS 0.7%CVE-2026-2269HIGHUncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File UploadEPSS 0.7%CVE-2024-24024CRITICALAn arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownEPSS 0.7%CVE-2024-24025CRITICALAn arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). EPSS 0.7%CVE-2025-34163CRITICALDongsheng Logistics Software Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2026-33582MEDIUMApache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory errorEPSS 0.7%CVE-2019-25714CRITICALSeeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservletEPSS 0.7%CVE-2023-31231CRITICALWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2024-7329MEDIUMYouDianCMS image_upload.php unrestricted uploadEPSS 0.7%CVE-2024-40394CRITICALSimple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the compoEPSS 0.7%CVE-2025-22152CRITICALImproper Path Validation Enables Path Traversal in Multiple Components in AtheosEPSS 0.7%CVE-2023-53950CRITICALInnovaStudio WYSIWYG Editor 5.4 Unrestricted File Upload via Filename ManipulationEPSS 0.7%CVE-2025-52353CRITICALAn arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embeEPSS 0.7%CVE-2025-2219MEDIUMLoveCards LoveCardsV2 image unrestricted uploadEPSS 0.7%CVE-2023-45188MEDIUMIBM Engineering Lifecycle Optimization Publishing file uploadEPSS 0.7%CVE-2026-24727CRITICALSUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous TypeEPSS 0.7%CVE-2024-32514CRITICALWordPress WP Poll Maker plugin <= 3.4 - Authenticated Arbitrary File Upload vulnerabilityEPSS 0.7%CVE-2026-71805CRITICALAn arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary fEPSS 0.7%