Weaknesses of type CWE-601

1,183 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2025-32693MEDIUMWordPress WebinarPress plugin <= 1.33.28 - Open Redirection VulnerabilityEPSS 0.4%CVE-2023-47779MEDIUMWordPress Integration for Contact Form 7 and Constant Contact Plugin <= 1.1.4 is vulnerable to Open RedirectionEPSS 0.4%CVE-2026-12049MEDIUMpgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameterEPSS 0.4%CVE-2026-70958CRITICALVulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). TheEPSS 0.4%CVE-2024-32129MEDIUMWordPress Freshdesk (official) plugin <= 2.3.6 - Open Redirection vulnerabilityEPSS 0.4%CVE-2021-25655MEDIUMURL redirection to untrusted site possible in Avaya Aura Experience PortalEPSS 0.4%CVE-2022-37927MEDIUMURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). EPSS 0.4%CVE-2024-20400MEDIUMA vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirectEPSS 0.4%CVE-2026-53573MEDIUMcore-geonetwork has an Open Redirect BypassEPSS 0.4%CVE-2026-3049MEDIUMhorilla-opensource horilla Query Parameter global_search.py get redirectEPSS 0.4%CVE-2023-20264MEDIUMA vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco AEPSS 0.4%CVE-2025-0705MEDIUMJoeyBling bootplus QrCodeController.java qrCode redirectEPSS 0.4%CVE-2024-0854MEDIUMURL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.EPSS 0.4%CVE-2024-31253MEDIUMWordPress WP OAuth Server (OAuth Authentication) plugin <= 4.3.3 - Open Redirection vulnerabilityEPSS 0.4%CVE-2024-34071MEDIUMOpen Redirect Bypass Protection EPSS 0.4%CVE-2023-32101MEDIUMWordPress Library Viewer Plugin <= 2.0.6 is vulnerable to Open RedirectionEPSS 0.4%CVE-2021-4260MEDIUMoils-js Web.js redirectEPSS 0.4%CVE-2023-49394MEDIUMZentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.EPSS 0.4%CVE-2026-47026HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions EPSS 0.4%CVE-2026-34931HIGHhoppscotch: Improper loopback redirect_uri validation in device-login flowEPSS 0.4%