Weaknesses of type CWE-601

1,176 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2023-23855MEDIUMSAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validatioEPSS 0.3%CVE-2025-14451MEDIUMSolutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' ParameterEPSS 0.3%CVE-2026-35302HIGHVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.EPSS 0.3%CVE-2026-81029HIGHOpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URIEPSS 0.3%CVE-2026-49456LOWWaku: Open Redirect via `unstable_redirect` HelperEPSS 0.3%CVE-2025-62716HIGHPlane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path ParameterEPSS 0.3%CVE-2023-4964HIGHPotential open redirect vulnerability in opentext SMAX and AMX product. EPSS 0.3%CVE-2025-6701MEDIUMXuxueli xxl-sso doLogin redirectEPSS 0.3%CVE-2026-56332MEDIUMCapgo - Open Redirect via confirmation_url ParameterEPSS 0.3%CVE-2026-49826NONEConcourse login flow has an open redirect issueEPSS 0.3%CVE-2025-21104MEDIUMDell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redirect') VulnerabilityEPSS 0.3%CVE-2022-46886MEDIUMThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrEPSS 0.3%CVE-2023-22641MEDIUMA url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, EPSS 0.3%CVE-2024-37141LOWDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low EPSS 0.3%CVE-2023-51675MEDIUMWordPress Advanced Access Manager Plugin <= 6.9.18 is vulnerable to Open RedirectionEPSS 0.3%CVE-2026-75114MEDIUMJoomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64EPSS 0.3%CVE-2025-50067CRITICALVulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 andEPSS 0.3%CVE-2026-2153MEDIUMmwielgoszewski doorman views.py is_safe_url redirectEPSS 0.3%CVE-2023-51517MEDIUMWordPress Calculated Fields Form Plugin <= 1.2.28 is vulnerable to Open RedirectionEPSS 0.3%CVE-2026-47347MEDIUMTYPO3 CMS - Open Redirect in Core UtilitiesEPSS 0.3%