Fallos del tipo CWE-601

1191 resultados

Redirecionamento para URL não validada (Open Redirect)

A aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro GET/POST, referer, etc.) sem validar se o destino é confiável. Um atacante pode usar isso para levar vítimas a sites maliciosos, phishing ou roubo de credenciais, enquanto a URL legítima da sua app aparece no clique inicial.

Ejemplo

Um site de e-commerce redireciona após login com `redirect.php?url=google.com`. Um atacante envia `redirect.php?url=seusite-fake.com` disfarçado de e-mail de confirmação. A vítima clica, vê a URL legítima na barra de endereço até o redirecionamento, e cai em um fake convincente.

Cómo mitigar

Valide a URL de destino contra uma whitelist de domínios permitidos ou, no mínimo, verifique se o host da URL é o seu próprio domínio antes de redirecionar. Nunca redirecione para URLs externas fornecidas pelo usuário sem controle explícito.

CVE-2025-59013MEDIUMOpen Redirect in TYPO3 CMSEPSS 0.2%CVE-2025-54088MEDIUMOpen Redirect in Secure Access prior to 14.10EPSS 0.2%CVE-2026-24847MEDIUMOpenEMR has Open Redirect in Eye Exam FormEPSS 0.2%CVE-2026-46894HIGHVulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affecteEPSS 0.2%CVE-2026-60648HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2025-1269MEDIUMOpen Redirect in HAVELSAN's Open Source Project Liman MYSEPSS 0.2%CVE-2026-1166MEDIUMOpen Redirect Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2025-1885MEDIUMOpen Redirect in Restajet's Online Food Delivery SystemEPSS 0.2%CVE-2025-61166MEDIUMAn open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.EPSS 0.2%CVE-2026-60640HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-26483MEDIUMDell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially expEPSS 0.2%CVE-2025-9072HIGHOne-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterEPSS 0.2%CVE-2025-55060MEDIUMPriority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')EPSS 0.2%CVE-2025-11222MEDIUMCentral Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via sEPSS 0.2%CVE-2025-9084LOWOpen redirect in OAuth loginEPSS 0.2%CVE-2026-24328MEDIUMOpen Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)EPSS 0.2%CVE-2026-46955HIGHVulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected arEPSS 0.2%CVE-2024-34328MEDIUMAn open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.EPSS 0.2%CVE-2025-66447NONEChamilo LMS has validation-less redirect on login pageEPSS 0.2%CVE-2026-60658HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%