Unrestricted file upload

Unrestricted file upload

Description

Failing to validate uploaded filenames, extensions, MIME types, and storage locations may allow executable files or dangerous content to be stored.

Potential impact

Attackers may upload web shells, distribute malicious files, or overwrite existing files.

Remediation

Use server-generated filenames, allow-list permitted extensions and MIME types, and prevent execution in the upload directory.

Examples

Before

php
<?php
$target = 'uploads/' . basename($_FILES['uploaded']['name']);
move_uploaded_file($_FILES['uploaded']['tmp_name'], $target);

After

php
<?php
if ($_FILES['uploaded']['error'] === UPLOAD_ERR_OK
    && mime_content_type($_FILES['uploaded']['tmp_name']) === 'image/png') {
    $target = '/var/app/uploads/' . bin2hex(random_bytes(16)) . '.png';
    move_uploaded_file($_FILES['uploaded']['tmp_name'], $target);
}

Explanation:

  • Before: The client-supplied filename is used without validating the type, extension, or storage destination.
  • After: The example checks upload status and content type, generates the filename on the server, and stores it outside executable paths.

This is a partial upload handler. Also enforce size limits, validate the permitted file format, and handle storage failures. Configure /var/app/uploads/ so the web server cannot execute files from it.

References