Description
Failing to validate uploaded filenames, extensions, MIME types, and storage locations may allow executable files or dangerous content to be stored.
Potential impact
Attackers may upload web shells, distribute malicious files, or overwrite existing files.
Remediation
Use server-generated filenames, allow-list permitted extensions and MIME types, and prevent execution in the upload directory.
Examples
Before
php
<?php
$target = 'uploads/' . basename($_FILES['uploaded']['name']);
move_uploaded_file($_FILES['uploaded']['tmp_name'], $target);
After
php
<?php
if ($_FILES['uploaded']['error'] === UPLOAD_ERR_OK
&& mime_content_type($_FILES['uploaded']['tmp_name']) === 'image/png') {
$target = '/var/app/uploads/' . bin2hex(random_bytes(16)) . '.png';
move_uploaded_file($_FILES['uploaded']['tmp_name'], $target);
}
Explanation:
- Before: The client-supplied filename is used without validating the type, extension, or storage destination.
- After: The example checks upload status and content type, generates the filename on the server, and stores it outside executable paths.
This is a partial upload handler. Also enforce size limits, validate the permitted file format, and handle storage failures. Configure /var/app/uploads/ so the web server cannot execute files from it.