Falhas do tipo CWE-434

3.080 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-50286HIGHA Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/toEPSS 9.6%CVE-2024-29272MEDIUMArbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and oEPSS 9.4%CVE-2025-54439HIGHUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affEPSS 9.0%CVE-2017-11154Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attaEPSS 8.6%CVE-2022-46604HIGHAn issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a craftEPSS 8.6%CVE-2021-24160Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File UploadEPSS 8.2%CVE-2021-27274CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System EPSS 8.2%CVE-2021-24212WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCEEPSS 7.9%CVE-2021-22937A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously cEPSS 7.8%CVE-2016-15043CRITICALWP Mobile Detector <= 3.5 - Arbitrary File UploadEPSS 7.8%CVE-2022-34128CRITICALThe Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.EPSS 7.8%CVE-2021-24236Imagements <= 1.2.5 - Unauthenticated Arbitrary File Upload to RCEEPSS 7.3%CVE-2020-36849CRITICALAIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File UploadEPSS 7.0%CVE-2020-36705CRITICALAdning Advertising <= 1.5.5 - Arbitrary File UploadEPSS 6.9%CVE-2021-34624CRITICALProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader ComponentEPSS 6.7%CVE-2017-3189The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file uploadEPSS 6.5%CVE-2020-20969HIGHFile Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.EPSS 6.2%CVE-2024-2561MEDIUM74CMS Company Logo Index.php#sendCompanyLogo unrestricted uploadEPSS 6.1%CVE-2021-37608Arbitrary file upload vulnerability in OFBizEPSS 6.0%CVE-2023-5144MEDIUMD-Link DAR-7000/DAR-8000 updateos.php unrestricted uploadEPSS 6.0%