File upload flaws
TL;DR
File upload flaws let an attacker put a dangerous file where it can do harm — classically a web shell that then runs on the server. The fix is to validate type properly, store uploads outside the web root, and never execute them.
Only test apps you’re authorised to test.
What it is
Anywhere an app lets you upload a file — an avatar, a document, an attachment — is a place where the wrong file, stored in the wrong place, can be trouble. The worst case is a file that the server will execute.
How it works
Weak checks are the theme: trusting the file extension, trusting the content-type header the browser sends, or storing uploads in a folder the web server will happily execute. If those line up, an uploaded script can become code running on the server.
How to test for it
- See what the app checks: extension, content-type, real file contents, size.
- Try mismatched types and see whether the check is on the header (weak) or the actual content.
- Work out where files land and whether that location is served or executed.
How to fix it
- Validate the actual content, not just the extension or header; allow-list expected types.
- Store uploads outside the web root and serve them via a handler, never let them execute.
- Rename files, strip metadata, and scan where appropriate.
Reference: the OWASP File Upload cheat sheet.