Weaknesses of type CWE-425

123 results

Falha em aplicar autorização em URLs, scripts ou arquivos restritos

A aplicação web não valida adequadamente se o usuário tem permissão para acessar determinadas URLs, scripts ou arquivos antes de entregar o conteúdo. Um invasor contorna a interface de autenticação acessando diretamente recursos protegidos via URL, explorando a ausência de verificação de autorização no servidor.

Example

Uma aplicação permite que qualquer usuário logado acesse /admin/relatorios/exportar.php digitando a URL diretamente, sem verificar se é administrador. Ou um PDF de contrato privado fica acessível em /uploads/contrato_123.pdf sem checagem de propriedade, permitindo download por qualquer pessoa que descubra o nome do arquivo.

How to mitigate

Implemente verificação de autorização em TODA rota/recurso sensível (não confie em obscuridade de URL): antes de servir o conteúdo, valide se o usuário logado tem a role/permissão necessária. Use middleware de autorização centralizado, whitelist de recursos públicos, e bloqueie por padrão.

CVE-2022-43110CRITICALVoltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system viaEPSS 0.7%CVE-2024-33897CRITICALA compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in EPSS 0.7%CVE-2023-44320MEDIUMA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAEPSS 0.6%CVE-2023-46186MEDIUMIBM Jazz for Service Management information disclosureEPSS 0.6%CVE-2024-6414MEDIUMParsec Automation TrakSYS Export Page contentpage direct requestEPSS 0.6%CVE-2022-42197MEDIUMIn Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modifyEPSS 0.6%CVE-2025-2147MEDIUMBeijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System file accessEPSS 0.6%CVE-2023-3426MEDIUMThe organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permissiEPSS 0.6%CVE-2026-10521HIGHAuthenticated unintended access to critical program parametersEPSS 0.6%CVE-2024-55075MEDIUMGrocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such EPSS 0.5%CVE-2026-42297HIGHArgo Workflows Is Missing Authorization in Sync ConfigMap ProviderEPSS 0.5%CVE-2024-2730MEDIUMPredictable Page Indexing Might Lead to Sensitive Data Exposure in MauticEPSS 0.5%CVE-2022-47700HIGHCOMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect AcceEPSS 0.5%CVE-2023-28160MEDIUMWhen following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking poEPSS 0.5%CVE-2025-15153MEDIUMPbootCMS SQLite Database pbootcms.db file accessEPSS 0.5%CVE-2024-7153MEDIUMNetgear WN604 siteSurvey.php direct requestEPSS 0.5%CVE-2024-0456MEDIUMDirect Request ('Forced Browsing') in GitLabEPSS 0.5%CVE-2023-45598MEDIUMA CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthentEPSS 0.5%CVE-2023-45596MEDIUMA CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remotEPSS 0.5%CVE-2026-13533MEDIUMagentejo Cockpit CMS htaccess config.yaml YAMLLoad file accessEPSS 0.5%