Fallos del tipo CWE-601

1186 resultados

Redirecionamento para URL não validada (Open Redirect)

A aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro GET/POST, referer, etc.) sem validar se o destino é confiável. Um atacante pode usar isso para levar vítimas a sites maliciosos, phishing ou roubo de credenciais, enquanto a URL legítima da sua app aparece no clique inicial.

Ejemplo

Um site de e-commerce redireciona após login com `redirect.php?url=google.com`. Um atacante envia `redirect.php?url=seusite-fake.com` disfarçado de e-mail de confirmação. A vítima clica, vê a URL legítima na barra de endereço até o redirecionamento, e cai em um fake convincente.

Cómo mitigar

Valide a URL de destino contra uma whitelist de domínios permitidos ou, no mínimo, verifique se o host da URL é o seu próprio domínio antes de redirecionar. Nunca redirecione para URLs externas fornecidas pelo usuário sem controle explícito.

CVE-2025-57800HIGHAudiobookshelf vulnerable to OIDC token exfiltration and account takeoverEPSS 0.5%CVE-2015-10113LOWWooFramework Tweaks Plugin wooframework-tweaks.php admin_screen_logic redirectEPSS 0.5%CVE-2026-10562MEDIUMUnauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web InterfaceEPSS 0.5%CVE-2015-10052MEDIUMcalesanz gibb-modul-151 login redirectEPSS 0.5%CVE-2024-46326MEDIUMPublic Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout functiEPSS 0.5%CVE-2022-41275MEDIUMIn SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a lEPSS 0.5%CVE-2022-3797MEDIUMeolinker apinto-dashboard login redirectEPSS 0.5%CVE-2024-54051MEDIUMAdobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.5%CVE-2023-48928MEDIUMFranklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.EPSS 0.5%CVE-2022-4589MEDIUMcyface Terms and Conditions Module views.py returnTo redirectEPSS 0.5%CVE-2026-48000MEDIUMAdobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.5%CVE-2024-54050MEDIUMAdobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)EPSS 0.5%CVE-2025-30781MEDIUMWordPress Scheduled & Automatic Order Status Controller for WooCommerce plugin <= 3.7.1 - Open Redirection VulnerabilityEPSS 0.5%CVE-2024-22400LOWOpen redirect in user_saml via RelayState parameter in Nextcloud User SamlEPSS 0.5%CVE-2025-62428HIGHDrawing-Captcha APP Host Header Injection in `/register` and `/confirm-email` EndpointsEPSS 0.5%CVE-2015-10102MEDIUMFreshdesk Plugin redirectEPSS 0.5%CVE-2023-5986HIGH A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scrEPSS 0.5%CVE-2025-55166MEDIUMsvg-sanitizer By-Passing Attribute SanitizationEPSS 0.4%CVE-2024-25559MEDIUMURL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator EPSS 0.4%CVE-2023-22958MEDIUMThe Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/piEPSS 0.4%