Weaknesses of type CWE-601

1,188 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2026-46894HIGHVulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affecteEPSS 0.2%CVE-2026-60648HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2026-24847MEDIUMOpenEMR has Open Redirect in Eye Exam FormEPSS 0.2%CVE-2025-1269MEDIUMOpen Redirect in HAVELSAN's Open Source Project Liman MYSEPSS 0.2%CVE-2026-1166MEDIUMOpen Redirect Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2025-1885MEDIUMOpen Redirect in Restajet's Online Food Delivery SystemEPSS 0.2%CVE-2025-61166MEDIUMAn open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.EPSS 0.2%CVE-2026-60640HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-26483MEDIUMDell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially expEPSS 0.2%CVE-2025-55060MEDIUMPriority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')EPSS 0.2%CVE-2025-9084LOWOpen redirect in OAuth loginEPSS 0.2%CVE-2025-9072HIGHOne-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterEPSS 0.2%CVE-2025-11222MEDIUMCentral Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via sEPSS 0.2%CVE-2026-24328MEDIUMOpen Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)EPSS 0.2%CVE-2026-46955HIGHVulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected arEPSS 0.2%CVE-2024-34328MEDIUMAn open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.EPSS 0.2%CVE-2025-66447NONEChamilo LMS has validation-less redirect on login pageEPSS 0.2%CVE-2026-60658HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-0608MEDIUMOpen Redirect in Logo Software's Logo CloudEPSS 0.2%CVE-2026-1369MEDIUMConditional CAPTCHA <= 4.0.0 - Open RedirectEPSS 0.2%