Weaknesses of type CWE-348

73 results

Uso de fonte menos confiável

A aplicação confia em dados ou instruções de uma fonte com menor nível de confiança (como entrada de usuário, rede não autenticada ou sistema terceiro) quando deveria usar uma fonte mais segura (como configuração local validada ou sistema interno autenticado). Isso permite que um atacante contamine decisões críticas do programa.

Example

Um sistema de pagamento que valida o valor da transação consultando um parâmetro enviado pelo cliente HTTP, em vez de recuperar o preço armazenado no banco de dados do servidor. Um atacante pode modificar o parâmetro e pagar menos do que deveria.

How to mitigate

Nunca confie em dados do cliente para decisões de segurança ou negócio críticas. Sempre valide e recupere informações sensíveis a partir de fontes internas (banco de dados, configuração do servidor) e use autenticação/autorização para qualquer dado externo que precise processar.

CVE-2026-63770HIGHGlance 0.8.5 IP Spoofing Authentication Brute-Force Protection BypassEPSS 0.3%CVE-2026-61682CRITICALkcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspaceEPSS 0.3%CVE-2026-57942MEDIUMLibreTranslate - IP Spoofing via X-Forwarded-For HeaderEPSS 0.3%CVE-2026-26927MEDIUMURL (HTTP Origin) call location spoofing in Szafir SDK WebEPSS 0.3%CVE-2022-44593LOWWordPress Solid Security plugin <= 9.3.1 - IP Spoofing Leading to Denial of Service vulnerabilityEPSS 0.3%CVE-2024-0789MEDIUMWP Maintenance <= 6.1.9.2 - IP Spoofing to Maintenance Mode BypassEPSS 0.3%CVE-2024-6171MEDIUMUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam BypassEPSS 0.2%CVE-2025-15154MEDIUMPbootCMS Header handle.php get_user_ip less trusted sourceEPSS 0.2%CVE-2022-4536MEDIUMIP Vault – WP Firewall <= 1.1 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-43634HIGHHestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP HeaderEPSS 0.2%CVE-2026-46415HIGHCaddy Defender trusted proxy client IP bypassEPSS 0.2%CVE-2025-13694MEDIUMAA Block country <= 1.0.1 - Unauthenticated IP Address Spoofing via X-Forwarded-For HeaderEPSS 0.2%CVE-2022-4529MEDIUMSecurity, Antivirus, Firewall – S.A.F <= 2.3.5 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-44183CRITICALCleanuparr: X-Forwarded-For leftmost parsing allows remote unauthenticated admin takeover when reverse-proxy mode is enabledEPSS 0.2%CVE-2022-4533MEDIUMLimit Login Attempts Plus <= 1.1.0 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-48772CRITICALProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACLEPSS 0.2%CVE-2022-4532MEDIUMLOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-9561HIGHEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP addrEPSS 0.2%CVE-2026-90711CRITICALproxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnetEPSS 0.2%CVE-2020-37248MEDIUMOfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle aEPSS 0.2%