Falhas do tipo CWE-434

3.091 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2026-45797MEDIUMHeyForm Vulnerable to Stored XSS via Unauthenticated SVG File UploadEPSS 0.6%CVE-2025-3585MEDIUMwestboy CicadasCMS JSP Parser upload unrestricted uploadEPSS 0.6%CVE-2025-3123MEDIUMWonderCMS Theme Installation/Plugin Installation installUpdateModuleAction unrestricted uploadEPSS 0.6%CVE-2025-3558MEDIUMghostxbh uzy-ssm-mall uploadUserHeadImage unrestricted uploadEPSS 0.6%CVE-2025-63227HIGHThe Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patEPSS 0.6%CVE-2024-53619MEDIUMAn authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uEPSS 0.6%CVE-2024-1532MEDIUMA vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor couEPSS 0.6%CVE-2024-2268MEDIUMkeerti1924 Online-Book-Store-Website unrestricted uploadEPSS 0.6%CVE-2024-56829CRITICALHuang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of theEPSS 0.6%CVE-2024-28425HIGHgreykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. ThiEPSS 0.6%CVE-2024-37424CRITICALWordPress Newspack Blocks plugin <= 3.0.8 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2024-2394MEDIUMSourceCodester Employee Management System add-admin.php unrestricted uploadEPSS 0.6%CVE-2026-28274HIGHInitiative Vulnerable to Token Theft via Stored XSS in Document UploadsEPSS 0.6%CVE-2025-10049HIGHResponsive Filterable Portfolio <= 1.0.24 - Authenticated (Admin+) Arbitrary File UploadEPSS 0.6%CVE-2024-46210HIGHAn arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploadinEPSS 0.6%CVE-2025-10001HIGHImport any XML, CSV or Excel File to WordPress <= 3.9.3 - Authenticated (Admin+) Limited Unsafe File UploadEPSS 0.6%CVE-2023-43269CRITICALpigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.EPSS 0.6%CVE-2024-25802CRITICALSKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the filEPSS 0.6%CVE-2025-3593MEDIUMZHENFENG13/code-projects My-Blog-layui authorImg upload unrestricted uploadEPSS 0.6%CVE-2025-2035MEDIUMs-a-zhd Ecommerce-Website-using-PHP customer_register.php unrestricted uploadEPSS 0.6%