Weaknesses of type CWE-601

1,187 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2025-53535LOWBetter Auth has an Open Redirect Vulnerability in originCheck Middleware Affecting Multiple RoutesEPSS 0.3%CVE-2024-31282MEDIUMWordPress App Builder plugin <= 3.8.7 - Open Redirection vulnerabilityEPSS 0.3%CVE-2024-3597HIGHExport WP Page to Static HTML/CSS <= 2.2.2 - Open RedirectEPSS 0.3%CVE-2024-47646MEDIUMWordPress Payflex Payment Gateway plugin <= 2.6.1 - Open Redirection vulnerabilityEPSS 0.3%CVE-2024-47354MEDIUMWordPress Simple Membership After Login Redirection plugin <= 1.6 - Open Redirection vulnerabilityEPSS 0.3%CVE-2025-55624MEDIUMAn intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-pEPSS 0.3%CVE-2025-10229MEDIUMFreshwork logout redirectEPSS 0.3%CVE-2025-49325MEDIUMWordPress Newspack Newsletters plugin <= 3.13.0 - Open Redirection VulnerabilityEPSS 0.3%CVE-2025-24020MEDIUMWeGIA Open Redirect vulnerabilityEPSS 0.3%CVE-2023-50963MEDIUMIBM Storage Defender HTTP HOST header injectionEPSS 0.3%CVE-2026-60467HIGHVulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affectedEPSS 0.3%CVE-2023-0681MEDIUMRapid7 Nexpose Uncontrolled URL RedirectEPSS 0.3%CVE-2026-40332MEDIUMMasa CMS open redirect via improper handling of scheme-relative URLsEPSS 0.3%CVE-2024-1240MEDIUMOpen Redirection in pyload/pyloadEPSS 0.3%CVE-2026-60945HIGHVulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions thaEPSS 0.3%CVE-2024-25676MEDIUMAn issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leadsEPSS 0.3%CVE-2023-31229MEDIUMWordPress WP Directory Kit Plugin <= 1.1.9 is vulnerable to Open RedirectionEPSS 0.3%CVE-2026-61078HIGHVulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application ObjectsEPSS 0.3%CVE-2024-44776MEDIUMAn Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a craftEPSS 0.3%CVE-2026-5467MEDIUMCasdoor OAuth Authorization Request redirectEPSS 0.3%