Weaknesses of type CWE-425

123 results

Falha em aplicar autorização em URLs, scripts ou arquivos restritos

A aplicação web não valida adequadamente se o usuário tem permissão para acessar determinadas URLs, scripts ou arquivos antes de entregar o conteúdo. Um invasor contorna a interface de autenticação acessando diretamente recursos protegidos via URL, explorando a ausência de verificação de autorização no servidor.

Example

Uma aplicação permite que qualquer usuário logado acesse /admin/relatorios/exportar.php digitando a URL diretamente, sem verificar se é administrador. Ou um PDF de contrato privado fica acessível em /uploads/contrato_123.pdf sem checagem de propriedade, permitindo download por qualquer pessoa que descubra o nome do arquivo.

How to mitigate

Implemente verificação de autorização em TODA rota/recurso sensível (não confie em obscuridade de URL): antes de servir o conteúdo, valide se o usuário logado tem a role/permissão necessária. Use middleware de autorização centralizado, whitelist de recursos públicos, e bloqueie por padrão.

CVE-2022-31484HIGHUser Account Deletion UnauthenticatedEPSS 1.0%CVE-2019-2388MEDIUMPotential exposure of log information in Ops ManagerEPSS 1.0%CVE-2024-24592CRITICALLack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily EPSS 1.0%CVE-2022-31480HIGHUnauthenticated Firmware Upload and Arbitrary RebootEPSS 0.9%CVE-2020-7541A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and ModiEPSS 0.9%CVE-2021-34588HIGHBender Charge Controller: Unprotected data exportEPSS 0.9%CVE-2022-2192HIGHForced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate EPSS 0.9%CVE-2022-42238HIGHA Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.EPSS 0.9%CVE-2024-7753MEDIUMSourceCodester Clinics Patient Management System user_images direct requestEPSS 0.9%CVE-2022-24385MEDIUMInformation disclosure via direct object access on SmarterTrack v100.0.8019.14010EPSS 0.9%CVE-2023-5786MEDIUMGeoServer GeoWebCache rest.html direct requestEPSS 0.8%CVE-2022-45276CRITICALAn issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account paEPSS 0.8%CVE-2022-31485MEDIUMUnauthenticated homepage note modificationEPSS 0.8%CVE-2026-0790MEDIUMALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-3792MEDIUMBeijing Netcon NS-ASG test_status.php direct requestEPSS 0.7%CVE-2025-6352MEDIUMcode-projects Automated Voting System Backend vote.php direct requestEPSS 0.7%CVE-2022-40845MEDIUMThe Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper autEPSS 0.7%CVE-2022-25626MEDIUMAn unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to cEPSS 0.7%CVE-2023-1682MEDIUMXunrui CMS Install.txt direct requestEPSS 0.7%CVE-2024-42001MEDIUMVonets WiFi Bridges Forced BrowsingEPSS 0.7%