Weaknesses of type CWE-601

1,187 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2024-4283MEDIUMURL Redirection to Untrusted Site ('Open Redirect') in GitLabEPSS 0.4%CVE-2026-47070MEDIUMHTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackneyEPSS 0.4%CVE-2025-7863MEDIUMthinkgem JeeSite ServletUtils.java redirectUrlEPSS 0.4%CVE-2022-26326MEDIUMPotential open redirection vulnerability in NetIQ Access Manager versions prior to version 5.0.2EPSS 0.4%CVE-2024-45981HIGHA host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction withEPSS 0.4%CVE-2026-22912MEDIUMImproper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to EPSS 0.4%CVE-2023-40306MEDIUMURL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)EPSS 0.4%CVE-2026-44598MEDIUMApache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)EPSS 0.4%CVE-2026-15093MEDIUMMultiple Vulnerabilities in IBM Engineering AI hub.EPSS 0.4%CVE-2023-31095MEDIUMWordPress Integration for Contact Form 7 HubSpot Plugin <= 1.2.8 is vulnerable to Open RedirectionEPSS 0.4%CVE-2024-22244MEDIUMHarbor Open Redirect URLEPSS 0.4%CVE-2025-23086MEDIUMOn most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector EPSS 0.4%CVE-2022-41965MEDIUMOpencast Authenticated OpenRedirect VulnerabilityEPSS 0.4%CVE-2023-2000MEDIUMUnrestricted navigation due to unvalidated mattermost server redirectionEPSS 0.4%CVE-2023-31237MEDIUMWordPress Zephyr Project Manager Plugin <= 3.3.9 is vulnerable to Open RedirectionEPSS 0.4%CVE-2025-54066MEDIUMDiracX-Web login page has Open Redirect vulnerabilityEPSS 0.4%CVE-2026-56326MEDIUMNuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateToEPSS 0.4%CVE-2022-36028CRITICALBigBlueButton Greenlight Open Redirect vulnerabilityEPSS 0.4%CVE-2022-27861MEDIUMWordPress Ninja Popups Plugin <= 4.7.5 is vulnerable to Open RedirectionEPSS 0.4%CVE-2025-2697HIGHIBM Cognos Command Center HTTP Open RedirectEPSS 0.4%