Weaknesses of type CWE-601

1,183 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2024-37881MEDIUMSiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirectEPSS 1.2%CVE-2021-22963A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a EPSS 1.2%CVE-2022-23078Habitica - Open redirect in login pageEPSS 1.2%CVE-2024-57241MEDIUMDedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resultEPSS 1.2%CVE-2023-28370MEDIUMOpen redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrarEPSS 1.1%CVE-2019-15073Openfind MAIL2000 Webmail Pre-Auth Open RedirectEPSS 1.1%CVE-2025-25198HIGHmailcow: dockerized vulnerable to password reset poisoningEPSS 1.1%CVE-2023-6927MEDIUMKeycloak: open redirect via "form_post.jwt" jarm response modeEPSS 1.1%CVE-2021-21338MEDIUMOpen Redirection in Login HandlingEPSS 1.1%CVE-2018-14658MEDIUMA flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.EPSS 1.1%CVE-2019-14882LOWA vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit pEPSS 1.1%CVE-2020-29498MEDIUMDell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentiallyEPSS 1.1%CVE-2019-1954MEDIUMCisco Webex Meetings Server Open Redirection VulnerabilityEPSS 1.1%CVE-2024-21641MEDIUMFlarum's Logout Route allows open redirectsEPSS 1.1%CVE-2022-35652An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attackeEPSS 1.1%CVE-2024-24763MEDIUMJumpServer Open Redirect VulnerabilityEPSS 1.1%CVE-2022-47500MEDIUMApache Helix: Open redirectEPSS 1.1%CVE-2021-41180MEDIUMGeolocation preview links can be set to arbitrary links in nextcloud talkEPSS 1.0%CVE-2022-0560MEDIUMOpen Redirect in microweber/microweberEPSS 1.0%CVE-2021-37699MEDIUMOpen Redirect in Next.js versions below 11.1.0EPSS 1.0%