Critical severity Vulnerability

Unrestricted File Upload

Uploads that are not type-checked or stored outside the web root become instant web shells.

Overview

The most direct route from "can upload" to "owns the server": the attacker uploads shell.php, requests it, and executes commands.\nWeak validation checks only the extension or the client-supplied MIME type, both of which are attacker-controlled.\nSafe designs store outside the web root, randomise filenames, re-encode images and serve through a non-executable domain.

Indicators of Compromise

Signals that suggest this is present on a system.

  • .php or .aspx accepted in uploads
  • Executable files reachable under /uploads
  • Double extensions such as image.php.jpg accepted

Controls that stop it

  • Validate and Constrain All Input

    Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used