Weaknesses of type CWE-601

1,177 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2024-33584MEDIUMWordPress Video Conferencing with Zoom plugin <= 4.4.4 - Open Redirection vulnerabilityEPSS 0.4%CVE-2023-45202MEDIUMOnline Examination System v1.0 - Multiple Open RedirectsEPSS 0.4%CVE-2023-45203MEDIUMOnline Examination System v1.0 - Multiple Open RedirectsEPSS 0.4%CVE-2025-0970MEDIUMZenvia Movidesk Login redirectEPSS 0.4%CVE-2023-41699MEDIUMPayara Platform: URL Redirection to untrusted site using FORM authenticationEPSS 0.4%CVE-2023-34247MEDIUM@keystone-6/auth Open Redirect vulnerabilityEPSS 0.4%CVE-2022-34474MEDIUMEven when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an externalEPSS 0.4%CVE-2023-5445MEDIUM An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL EPSS 0.4%CVE-2026-47377MEDIUMNocoDB: Open Redirect via Hash Fragment in hashRedirect PluginEPSS 0.4%CVE-2024-28113LOWOpen redirection using the return_url parameter in Peering ManagerEPSS 0.4%CVE-2023-47168MEDIUMOpen redirect in /oauth/<service>/mobile_login?redirect_to=EPSS 0.4%CVE-2023-0042MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 priorEPSS 0.4%CVE-2024-46886MEDIUMThe web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to makEPSS 0.4%CVE-2026-34847MEDIUMhoppscotch: Open redirect via `/enter?redirect=`EPSS 0.4%CVE-2024-31213LOWInstantCMS Open Redirect vulnerabilityEPSS 0.4%CVE-2022-2237MEDIUMA flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSsEPSS 0.4%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.4%CVE-2024-52003MEDIUMX-Forwarded-Prefix Header still allows for Open Redirect in traefikEPSS 0.4%CVE-2026-33102CRITICALMicrosoft 365 Copilot Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-20886HIGHVMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attackeEPSS 0.4%