Weaknesses of type CWE-348

73 results

Uso de fonte menos confiável

A aplicação confia em dados ou instruções de uma fonte com menor nível de confiança (como entrada de usuário, rede não autenticada ou sistema terceiro) quando deveria usar uma fonte mais segura (como configuração local validada ou sistema interno autenticado). Isso permite que um atacante contamine decisões críticas do programa.

Example

Um sistema de pagamento que valida o valor da transação consultando um parâmetro enviado pelo cliente HTTP, em vez de recuperar o preço armazenado no banco de dados do servidor. Um atacante pode modificar o parâmetro e pagar menos do que deveria.

How to mitigate

Nunca confie em dados do cliente para decisões de segurança ou negócio críticas. Sempre valide e recupere informações sensíveis a partir de fontes internas (banco de dados, configuração do servidor) e use autenticação/autorização para qualquer dado externo que precise processar.

CVE-2025-27913LOWPassbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), canEPSS 0.2%CVE-2026-59897MEDIUMHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationEPSS 0.2%CVE-2026-54289MEDIUMHono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restEPSS 0.2%CVE-2025-24856MEDIUMAn issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows aEPSS 0.2%CVE-2025-53522MEDIUMMovable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unaEPSS 0.2%CVE-2026-33690MEDIUMAVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()EPSS 0.2%CVE-2026-25552MEDIUMGhost CLI < 1.30.1 IP Spoofing via X-Forwarded-For HeaderEPSS 0.2%CVE-2025-1245MEDIUMBypass Connection Restriction Vulnerability in Hitachi Ops Center AnalyzerEPSS 0.2%CVE-2025-47149MEDIUMThe optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product mEPSS 0.2%CVE-2026-62987MEDIUMFabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection headerEPSS 0.2%CVE-2026-90679MEDIUMForgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not EPSS 0.2%CVE-2024-54840MEDIUMPVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues EPSS 0.2%CVE-2026-59999MEDIUMIn sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.EPSS 0.2%CVE-2026-61589MEDIUMdjust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live pathEPSS 0.2%CVE-2026-22201MEDIUMwpDiscuz before 7.6.47 - IP Address Spoofing in getIP()EPSS 0.2%CVE-2025-47424HIGHRetool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host headerEPSS 0.2%CVE-2026-46466LOWDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.2%CVE-2025-69240HIGHHeader Poisoning in Raytha CMSEPSS 0.1%CVE-2026-16272CRITICALClient IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS ModuleEPSS 0.1%CVE-2026-12249CRITICALCanonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentEPSS 0.1%