Weaknesses of type CWE-601

1,186 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2025-57800HIGHAudiobookshelf vulnerable to OIDC token exfiltration and account takeoverEPSS 0.5%CVE-2015-10113LOWWooFramework Tweaks Plugin wooframework-tweaks.php admin_screen_logic redirectEPSS 0.5%CVE-2026-10562MEDIUMUnauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web InterfaceEPSS 0.5%CVE-2015-10052MEDIUMcalesanz gibb-modul-151 login redirectEPSS 0.5%CVE-2024-46326MEDIUMPublic Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout functiEPSS 0.5%CVE-2022-41275MEDIUMIn SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a lEPSS 0.5%CVE-2022-3797MEDIUMeolinker apinto-dashboard login redirectEPSS 0.5%CVE-2024-54051MEDIUMAdobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.5%CVE-2023-48928MEDIUMFranklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.EPSS 0.5%CVE-2022-4589MEDIUMcyface Terms and Conditions Module views.py returnTo redirectEPSS 0.5%CVE-2026-48000MEDIUMAdobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.5%CVE-2024-54050MEDIUMAdobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.5%CVE-2025-30781MEDIUMWordPress Scheduled & Automatic Order Status Controller for WooCommerce plugin <= 3.7.1 - Open Redirection VulnerabilityEPSS 0.5%CVE-2024-22400LOWOpen redirect in user_saml via RelayState parameter in Nextcloud User SamlEPSS 0.5%CVE-2025-62428HIGHDrawing-Captcha APP Host Header Injection in `/register` and `/confirm-email` EndpointsEPSS 0.5%CVE-2015-10102MEDIUMFreshdesk Plugin redirectEPSS 0.5%CVE-2023-5986HIGH A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scrEPSS 0.5%CVE-2025-55166MEDIUMsvg-sanitizer By-Passing Attribute SanitizationEPSS 0.4%CVE-2024-25559MEDIUMURL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator EPSS 0.4%CVE-2023-22958MEDIUMThe Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/piEPSS 0.4%