Weaknesses of type CWE-601

1,177 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2026-58450MEDIUMInvoice Ninja 5.13.26 - Open Redirect in Client Portal Login via intended ParameterEPSS 0.3%CVE-2024-0319MEDIUMOpen Redirect vulnerability in FireEye HXToolEPSS 0.3%CVE-2026-49820MEDIUMProbo has an open redirect bypass via path normalizationEPSS 0.3%CVE-2024-46481HIGHThe login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.EPSS 0.3%CVE-2026-0508HIGHOpen Redirect vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.3%CVE-2026-73191MEDIUMApache Syncope: CAS service URL injection via Forwarded HTTP headersEPSS 0.3%CVE-2026-23817MEDIUMUnauthenticated Open Redirect allows URL Manipulation in Web InterfaceEPSS 0.3%CVE-2022-38657HIGHAn open redirect to malicious sites affects HCL LeapEPSS 0.3%CVE-2026-40905HIGHLinkAce: Password Reset Poisoning via X-Forwarded-Host Header Injection Leading to Account TakeoverEPSS 0.3%CVE-2026-82731LOWUnescaped path parameters in AshTypescript generated TypeScript client allow request redirectionEPSS 0.3%CVE-2026-80200MEDIUMKimai before 2.53.0 Open Redirect via RelayStateEPSS 0.3%CVE-2025-30010MEDIUMMultiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)EPSS 0.3%CVE-2025-1488MEDIUMWPO365 | MICROSOFT 365 GRAPH MAILER <= 3.2 - Open Redirect via 'redirect_to' ParameterEPSS 0.3%CVE-2026-60641HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.3%CVE-2025-54196MEDIUMAdobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.3%CVE-2026-24768MEDIUMNocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn ParameterEPSS 0.3%CVE-2025-10355MEDIUMOpen redirection vulnerability in MOLGENIS EMX2EPSS 0.3%CVE-2026-83320HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are EPSS 0.3%CVE-2025-5183MEDIUMSummer Pearl Group Vacation Rental Management Platform Header redirectEPSS 0.3%CVE-2026-89307MEDIUMHTML injection allows open redirection in WordPress theme design-scuole-wordpress-themeEPSS 0.3%