Falhas do tipo CWE-434

3.091 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2025-13376HIGHProjectList <= 0.3.0 - Authenticated (Editor+) Arbitrary File UploadEPSS 0.6%CVE-2025-57795CRITICALUnauthenticated Remote File Download in Explorance BlueEPSS 0.6%CVE-2024-27957CRITICALWordPress Pie Register plugin <= 3.8.3.1 - Unauthenticated Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2024-48180CRITICALClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/teEPSS 0.6%CVE-2026-14553HIGHZportals < 6.3.4 - Subscriber+ Arbitrary File UploadEPSS 0.6%CVE-2025-6802CRITICALMarvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-58313HIGHxbtitFM 4.1.18 Insecure File Upload in file_hosting FeatureEPSS 0.6%CVE-2026-71620HIGHFile Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php fileEPSS 0.6%CVE-2025-39557CRITICALWordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2024-2529MEDIUMMAGESH-K21 Online-College-Event-Hall-Reservation-System rooms.php unrestricted uploadEPSS 0.6%CVE-2024-43662MEDIUMAuthenticated arbitrary file upload to /tmp/ and /tmp/upload/EPSS 0.6%CVE-2025-7438HIGHMasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.6%CVE-2023-7159MEDIUMgopeak MasterLab User.php update unrestricted uploadEPSS 0.6%CVE-2025-12682CRITICALEasy Upload Files During Checkout <= 2.9.8 - Unauthenticated Arbitrary JavaScript File UploadEPSS 0.6%CVE-2024-3117MEDIUMYouDianCMS ChannelAction.class.php unrestricted uploadEPSS 0.6%CVE-2023-2063MEDIUMInformation disclosure, tampering, deletion and destruction vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.6%CVE-2024-1921MEDIUMosuuu LightPicture Setup.php unrestricted uploadEPSS 0.6%CVE-2023-51417CRITICALWordPress JVM rich text icons Plugin <= 1.2.3 is vulnerable to Arbitrary File UploadEPSS 0.6%CVE-2023-51410CRITICALWordPress WP Mail Log Plugin <= 1.1.2 is vulnerable to Arbitrary File UploadEPSS 0.6%CVE-2024-53863HIGHSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decodersEPSS 0.6%