Weaknesses of type CWE-601

1,177 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2026-33102CRITICALMicrosoft 365 Copilot Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-41207MEDIUMSAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use EPSS 0.4%CVE-2024-56734HIGHBetter Auth has an Open Redirect Vulnerability in Verify Email EndpointEPSS 0.4%CVE-2024-22854MEDIUMDOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has EPSS 0.4%CVE-2024-22113MEDIUMOpen redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attaEPSS 0.4%CVE-2025-48936HIGHZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header InjectionEPSS 0.4%CVE-2026-43941CRITICALUnvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link clickEPSS 0.4%CVE-2025-54145CRITICALScanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websitesEPSS 0.4%CVE-2023-35948MEDIUMNovu Open Redirect Vulnerability in Sign-In with GitHub FunctionalityEPSS 0.4%CVE-2024-47530MEDIUMScout contains an Open Redirect on Login via `next`EPSS 0.4%CVE-2023-45762MEDIUMWordPress Responsive Column Widgets Plugin <= 1.2.7 is vulnerable to Open RedirectionEPSS 0.4%CVE-2025-61587LOWWeblate integration with Anubis can lead to Open Redirect via redir parameterEPSS 0.4%CVE-2026-24052HIGHClaude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled DomainsEPSS 0.4%CVE-2023-45201MEDIUMOnline Examination System v1.0 - Multiple Open RedirectsEPSS 0.4%CVE-2026-77386MEDIUMKyoo: OIDC login token can be redirected to an attacker-controlled URLEPSS 0.4%CVE-2023-47548MEDIUMWordPress Integrate Google Drive Plugin <= 1.3.2 is vulnerable to Open RedirectionEPSS 0.4%CVE-2023-48325MEDIUMWordPress Landing Page Builder Plugin <= 1.5.1.5 is vulnerable to Open RedirectionEPSS 0.4%CVE-2023-31245HIGH Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP EPSS 0.4%CVE-2024-39097MEDIUMThere is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.EPSS 0.4%CVE-2026-35259HIGHVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.EPSS 0.4%