Fallos del tipo CWE-601

1190 resultados

Redirecionamento para URL não validada (Open Redirect)

A aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro GET/POST, referer, etc.) sem validar se o destino é confiável. Um atacante pode usar isso para levar vítimas a sites maliciosos, phishing ou roubo de credenciais, enquanto a URL legítima da sua app aparece no clique inicial.

Ejemplo

Um site de e-commerce redireciona após login com `redirect.php?url=google.com`. Um atacante envia `redirect.php?url=seusite-fake.com` disfarçado de e-mail de confirmação. A vítima clica, vê a URL legítima na barra de endereço até o redirecionamento, e cai em um fake convincente.

Cómo mitigar

Valide a URL de destino contra uma whitelist de domínios permitidos ou, no mínimo, verifique se o host da URL é o seu próprio domínio antes de redirecionar. Nunca redirecione para URLs externas fornecidas pelo usuário sem controle explícito.

CVE-2026-11477MEDIUMhs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirectEPSS 0.3%CVE-2023-23855MEDIUMSAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validatioEPSS 0.3%CVE-2025-14451MEDIUMSolutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' ParameterEPSS 0.3%CVE-2023-4964HIGHPotential open redirect vulnerability in opentext SMAX and AMX product. EPSS 0.3%CVE-2025-6701MEDIUMXuxueli xxl-sso doLogin redirectEPSS 0.3%CVE-2022-46886MEDIUMThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrEPSS 0.3%CVE-2025-21104MEDIUMDell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redirect') VulnerabilityEPSS 0.3%CVE-2026-56332MEDIUMCapgo - Open Redirect via confirmation_url ParameterEPSS 0.3%CVE-2023-22641MEDIUMA url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, EPSS 0.3%CVE-2024-37141LOWDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low EPSS 0.3%CVE-2023-51675MEDIUMWordPress Advanced Access Manager Plugin <= 6.9.18 is vulnerable to Open RedirectionEPSS 0.3%CVE-2026-41706MEDIUMOpen Redirect When Using CookieRequestCacheEPSS 0.3%CVE-2026-46616MEDIUMUmbraco.Cms: Open Redirect Vulnerability in Surface ControllersEPSS 0.3%CVE-2026-81423MEDIUMAccept Stripe Payments < 2.1.4 - Open Redirect via IPN HandlerEPSS 0.3%CVE-2026-31819MEDIUMSylius has an Open Redirect via Referer HeaderEPSS 0.3%CVE-2026-28194MEDIUMIn JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flowEPSS 0.3%CVE-2026-42230MEDIUMn8n: Open Redirect in MCP OAuth Consent FlowEPSS 0.3%CVE-2025-62595MEDIUMKoa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect LogicEPSS 0.3%CVE-2023-51517MEDIUMWordPress Calculated Fields Form Plugin <= 1.2.28 is vulnerable to Open RedirectionEPSS 0.3%CVE-2026-28415MEDIUMGradio has Open Redirect in OAuth FlowEPSS 0.3%