Fallos del tipo CWE-601

1191 resultados

Redirecionamento para URL não validada (Open Redirect)

A aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro GET/POST, referer, etc.) sem validar se o destino é confiável. Um atacante pode usar isso para levar vítimas a sites maliciosos, phishing ou roubo de credenciais, enquanto a URL legítima da sua app aparece no clique inicial.

Ejemplo

Um site de e-commerce redireciona após login com `redirect.php?url=google.com`. Um atacante envia `redirect.php?url=seusite-fake.com` disfarçado de e-mail de confirmação. A vítima clica, vê a URL legítima na barra de endereço até o redirecionamento, e cai em um fake convincente.

Cómo mitigar

Valide a URL de destino contra uma whitelist de domínios permitidos ou, no mínimo, verifique se o host da URL é o seu próprio domínio antes de redirecionar. Nunca redirecione para URLs externas fornecidas pelo usuário sem controle explícito.

CVE-2025-64250MEDIUMWordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerabilityEPSS 0.2%CVE-2026-34284MEDIUMVulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). SupportEPSS 0.2%CVE-2026-47002MEDIUMVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versEPSS 0.2%CVE-2024-4604MEDIUMOpen Redirect in Magarsus Consultancy's SSOEPSS 0.2%CVE-2025-8129MEDIUMKoaJS Koa HTTP Header response.js back redirectEPSS 0.2%CVE-2026-17912MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigationEPSS 0.2%CVE-2026-40096MEDIUMimmich: Open Redirect via Shared Album nameEPSS 0.2%CVE-2024-21734LOWURL Redirection vulnerability in SAP Marketing (Contacts App)EPSS 0.2%CVE-2024-55892MEDIUMPotential Open Redirect via Parsing Differences in TYPO3EPSS 0.2%CVE-2025-24741MEDIUMWordPress KB Support plugin <= 1.6.7 - Open Redirection vulnerabilityEPSS 0.2%CVE-2024-45082MEDIUMIBM Cognos Analytics HTTP open redirectionEPSS 0.2%CVE-2026-47015HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported versioEPSS 0.2%CVE-2025-52219MEDIUMSelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to cEPSS 0.2%CVE-2024-42341MEDIUMLoway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')EPSS 0.2%CVE-2026-42207MEDIUMMagento LTS: Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` - magento-ltsEPSS 0.2%CVE-2026-47887MEDIUMSpring Framework Open Redirect in UrlFileNameViewControllerEPSS 0.2%CVE-2025-57821MEDIUMBasecamp's Google Sign-In for Rails allowed redirects to a malformed URLEPSS 0.2%CVE-2025-67852LOWMoodle: moodle: open redirect vulnerability in oauth login flow allows redirection to malicious sites.EPSS 0.2%CVE-2026-78377MEDIUMOpen Redirect in Yordam Informatics's Library Automation SystemEPSS 0.2%CVE-2026-23726MEDIUMWeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=listarTodos, nomeClasse=TipoEntradaControle)EPSS 0.2%