Weaknesses of type CWE-601

1,188 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2026-53523MEDIUMNezha Monitoring: OAuth2 Redirect URL — Host Header InjectionEPSS 0.2%CVE-2025-70032MEDIUMAn issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.EPSS 0.2%CVE-2025-43795MEDIUMOpen redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , EPSS 0.2%CVE-2026-49996LOWsecuredrop-proxy origin limitation can be bypassed with redirectsEPSS 0.2%CVE-2025-71403HIGHbetter-auth before 1.1.20 Open Redirect via trustedOrigins BypassEPSS 0.2%CVE-2025-13819MEDIUMOpen redirect in web server of MiR robots and MiR fleetEPSS 0.2%CVE-2025-64115MEDIUMMovary unvalidated Referer header allows open redirect and phishingEPSS 0.2%CVE-2024-30140MEDIUMHCL BigFix Compliance is affected by unvalidated redirects and forwardsEPSS 0.2%CVE-2025-8737MEDIUMzlt2000 microservices-platform OauthLogoutSuccessHandler.java onLogoutSuccess redirectEPSS 0.2%CVE-2025-20378LOWOpen Redirect on Web Login endpoint in Splunk EnterpriseEPSS 0.2%CVE-2025-20291MEDIUMA vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user toEPSS 0.2%CVE-2024-45082MEDIUMIBM Cognos Analytics HTTP open redirectionEPSS 0.2%CVE-2025-42985MEDIUMOpen Redirect vulnerability in SAP BusinessObjects Content Administrator workbenchEPSS 0.2%CVE-2026-22032MEDIUMDirectus has open redirect in SAMLEPSS 0.2%CVE-2026-33510HIGHDOM-Based XSS in Homarr /auth/login RedirectEPSS 0.2%CVE-2026-73734MEDIUMUnauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabric Composer Web InterfaceEPSS 0.2%CVE-2025-64116MEDIUMMovary vulnerable to an open redirectEPSS 0.2%CVE-2025-62253MEDIUMOpen redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXPEPSS 0.2%CVE-2025-61753MEDIUMVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected aEPSS 0.2%CVE-2026-21295LOWAdobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.2%