Fallos del tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

É quando o software aceita dados sem validar adequadamente se vieram de uma fonte legítima e confiável. O sistema confia em informações (mensagens, arquivos, requisições) sem confirmar sua origem ou integridade, permitindo que um atacante forje, modifique ou injete dados maliciosos que serão processados como se fossem legítimos.

Ejemplo

Um serviço aceita atualizações de configuração via JSON sem verificar assinatura digital ou token HMAC. Um atacante intercepta a requisição e modifica o payload para redirecionar logs para um servidor controlado por ele — e o serviço aplica a mudança porque 'recebeu um JSON válido'.

Cómo mitigar

Implemente autenticação criptográfica de dados: use assinatura digital (HMAC, RSA, ECDSA) ou tokens com validade (JWT com chave secreta), valide sempre a origem da mensagem antes de processar, e recuse dados sem prova de autenticidade. Não confie apenas em formato válido ou canal de transporte — valide origem e integridade.

CVE-2026-83537MEDIUMWP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_paymentEPSS 0.1%CVE-2026-84043MEDIUMePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation BypassEPSS 0.1%CVE-2026-92400MEDIUMPayment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment ConfusionEPSS 0.1%CVE-2026-86809MEDIUMPersian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority BypassEPSS 0.1%CVE-2024-54111MEDIUMRead/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.1%CVE-2026-83533MEDIUMWP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_paymentEPSS 0.1%CVE-2026-15148MEDIUMWP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOREPSS 0.1%CVE-2023-22315MEDIUM Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates EPSS 0.1%CVE-2026-82215MEDIUMWC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified WebhookEPSS 0.1%CVE-2021-26396MEDIUMInsufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. EPSS 0.1%CVE-2026-78296MEDIUMWordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerabilityEPSS 0.1%CVE-2026-15211MEDIUMSubscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture TokenEPSS 0.1%CVE-2026-15239MEDIUMSimple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache KeyEPSS 0.1%CVE-2026-24775MEDIUMOpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor ExtensionEPSS 0.1%CVE-2026-33243HIGHbarebox: FIT Signature Verification Bypass VulnerabilityEPSS 0.1%CVE-2026-45792MEDIUMRTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLMEPSS 0.1%CVE-2026-15246MEDIUMRealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment BypassEPSS 0.1%CVE-2026-28145MEDIUMWordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerabilityEPSS 0.1%CVE-2026-46654HIGHPlonky3 MultiField32Challenger: transcript malleability and challenge entropy lossEPSS 0.1%CVE-2026-32323HIGHMullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installerEPSS 0.1%