Weaknesses of type CWE-451

387 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2021-41598UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to userEPSS 1.2%CVE-2025-21404MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 1.1%CVE-2021-22866UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesEPSS 1.0%CVE-2020-7369MEDIUMYandex Browser Address Bar SpooofingEPSS 1.0%CVE-2020-7371MEDIUMRaise IT Solutions RITS Browser Address Bar SpooofingEPSS 1.0%CVE-2020-7370MEDIUMDanyil Vasilenko Bolt Browser Address Bar SpooofingEPSS 1.0%CVE-2024-4950MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage iEPSS 0.9%CVE-2023-2938MEDIUMInappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised theEPSS 0.9%CVE-2023-2937MEDIUMInappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised theEPSS 0.9%CVE-2025-43228MEDIUMThe issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may leaEPSS 0.9%CVE-2024-0750HIGHA bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vEPSS 0.8%CVE-2025-29825MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.8%CVE-2025-64667MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 0.8%CVE-2022-34479MEDIUMA malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potEPSS 0.7%CVE-2020-7363MEDIUMUCWeb UC Browser Address Bar SpooofingEPSS 0.7%CVE-2020-7364MEDIUMUCWeb UC Browser Address Bar SpooofingEPSS 0.7%CVE-2024-2631MEDIUMInappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 0.7%CVE-2021-33593Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may EPSS 0.7%CVE-2023-0700MEDIUMInappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contentsEPSS 0.7%CVE-2022-3313MEDIUMIncorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTEPSS 0.7%