Weaknesses of type CWE-425

123 results

Falha em aplicar autorização em URLs, scripts ou arquivos restritos

A aplicação web não valida adequadamente se o usuário tem permissão para acessar determinadas URLs, scripts ou arquivos antes de entregar o conteúdo. Um invasor contorna a interface de autenticação acessando diretamente recursos protegidos via URL, explorando a ausência de verificação de autorização no servidor.

Example

Uma aplicação permite que qualquer usuário logado acesse /admin/relatorios/exportar.php digitando a URL diretamente, sem verificar se é administrador. Ou um PDF de contrato privado fica acessível em /uploads/contrato_123.pdf sem checagem de propriedade, permitindo download por qualquer pessoa que descubra o nome do arquivo.

How to mitigate

Implemente verificação de autorização em TODA rota/recurso sensível (não confie em obscuridade de URL): antes de servir o conteúdo, valide se o usuário logado tem a role/permissão necessária. Use middleware de autorização centralizado, whitelist de recursos públicos, e bloqueie por padrão.

CVE-2025-1542CRITICALImproper permission control in OXARI ServiceDeskEPSS 0.4%CVE-2026-1978MEDIUMkalyan02 NanoCMS User Information pagesdata.txt direct requestEPSS 0.4%CVE-2025-27581MEDIUMNIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET moEPSS 0.4%CVE-2025-46690MEDIUMVerverica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.EPSS 0.4%CVE-2024-39868HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate theEPSS 0.4%CVE-2024-39867HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate theEPSS 0.4%CVE-2025-48207HIGHThe reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.EPSS 0.4%CVE-2025-48205HIGHThe sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.EPSS 0.4%CVE-2025-48201HIGHThe ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.EPSS 0.4%CVE-2023-22834LOWThe contour service was not checking that users had permission to create an analysis for a given datasetEPSS 0.4%CVE-2025-15381HIGHUnauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflowEPSS 0.3%CVE-2025-6195MEDIUMDirect Request ('Forced Browsing') in GitLabEPSS 0.3%CVE-2026-40532MEDIUMA direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-7280EPSS 0.3%CVE-2025-14697MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management System ExportFiles file accessEPSS 0.3%CVE-2024-9945MEDIUMLimited Information Disclosure in GoAnywhere MFT Prior to 7.7.0EPSS 0.3%CVE-2026-19903MEDIUMSourceCodester Online Clothing Store SQL Database Backup shopping.sql file accessEPSS 0.3%CVE-2025-26381MEDIUMOpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems)EPSS 0.3%CVE-2026-11986MEDIUMKeycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloakEPSS 0.3%CVE-2025-52920MEDIUMInnoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a custoEPSS 0.3%CVE-2025-48202MEDIUMThe femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.EPSS 0.3%