Falhas do tipo CWE-434

3.091 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2023-53942CRITICALFile Thingie 2.5.7 Authenticated Arbitrary File Upload Remote Code ExecutionEPSS 0.6%CVE-2025-32957HIGHbaserCMS: unsafe File Upload Leading to Remote Code Execution (RCE)EPSS 0.6%CVE-2024-51792CRITICALWordPress Audio Record plugin <= 1.0 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2024-5911HIGHPAN-OS: File Upload Vulnerability in the Panorama Web InterfaceEPSS 0.6%CVE-2024-9280MEDIUMkalvinGit kvf-admin FileUploadKit.java fileUpload unrestricted uploadEPSS 0.6%CVE-2023-20196MEDIUMTwo vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit tEPSS 0.6%CVE-2024-22550MEDIUMAn arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code EPSS 0.6%CVE-2024-52490CRITICALWordPress Pathomation plugin <= 2.5.1 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2023-50717MEDIUMNocoDB Allows Preview of File with Dangerous ContentEPSS 0.6%CVE-2025-13062HIGHSupreme Modules Lite <= 2.5.62 - Authenticated (Author+) Arbitrary File Upload via JSON Upload BypassEPSS 0.6%CVE-2026-100389CRITICALGestSup before 3.2.61 Remote Code Execution via IMAP AttachmentEPSS 0.6%CVE-2023-41812MEDIUMUploading executables via the file managerEPSS 0.6%CVE-2024-13191MEDIUMZeroWdd myblog uploadController.java upload unrestricted uploadEPSS 0.6%CVE-2023-6794MEDIUMPAN-OS: File Upload Vulnerability in the Web InterfaceEPSS 0.6%CVE-2025-9112HIGHDoccure <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.6%CVE-2024-12700HIGHTibbo AggreGate Network Manager Unrestricted Upload of File with Dangerous TypeEPSS 0.6%CVE-2024-12478MEDIUMInvoicePlane 1 upload_file unrestricted uploadEPSS 0.6%CVE-2026-13249CRITICALUnauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040EPSS 0.6%CVE-2025-12057CRITICALWavePlayer < 3.8.0 - Unauthenticated Arbitrary File UploadEPSS 0.6%CVE-2026-45797MEDIUMHeyForm Vulnerable to Stored XSS via Unauthenticated SVG File UploadEPSS 0.6%