Fallos del tipo CWE-601

1191 resultados

Redirecionamento para URL não validada (Open Redirect)

A aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro GET/POST, referer, etc.) sem validar se o destino é confiável. Um atacante pode usar isso para levar vítimas a sites maliciosos, phishing ou roubo de credenciais, enquanto a URL legítima da sua app aparece no clique inicial.

Ejemplo

Um site de e-commerce redireciona após login com `redirect.php?url=google.com`. Um atacante envia `redirect.php?url=seusite-fake.com` disfarçado de e-mail de confirmação. A vítima clica, vê a URL legítima na barra de endereço até o redirecionamento, e cai em um fake convincente.

Cómo mitigar

Valide a URL de destino contra uma whitelist de domínios permitidos ou, no mínimo, verifique se o host da URL é o seu próprio domínio antes de redirecionar. Nunca redirecione para URLs externas fornecidas pelo usuário sem controle explícito.

CVE-2026-1369MEDIUMConditional CAPTCHA <= 4.0.0 - Open RedirectEPSS 0.2%CVE-2025-0608MEDIUMOpen Redirect in Logo Software's Logo CloudEPSS 0.2%CVE-2024-8527HIGHALC WebCTRL Carrier i-Vu Open Redirect via URL parameterEPSS 0.2%CVE-2025-66596MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request hEPSS 0.2%CVE-2025-55032MEDIUMFocus incorrectly ignores Content-Disposition headers for some MIME typesEPSS 0.2%CVE-2026-62517MEDIUMVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2026-2376MEDIUMMirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interfaceEPSS 0.2%CVE-2026-60642HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-62690LOWOpen redirect in error page when link opened in new tabEPSS 0.1%CVE-2026-10856MEDIUMOpen redirect in MISP dashboard button widget URL handlingEPSS 0.1%CVE-2025-2068MEDIUMAn open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a locEPSS 0.1%CVE-2024-58342MEDIUMXenForo Open Redirect via getDynamicRedirectEPSS 0.1%CVE-2026-18505MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2025-32748MEDIUMDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remoEPSS 0.1%CVE-2026-21826MEDIUMHCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injectionEPSS 0.1%CVE-2026-34083MEDIUMsignalk-server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC FlowEPSS 0.1%CVE-2025-27900MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.1%CVE-2026-80444MEDIUMUnauthenticated Open Redirect Vulnerability in Abis Technology's AVESİSEPSS 0.1%CVE-2024-13983MEDIUMInappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a cEPSS 0.1%CVE-2026-60685MEDIUMVulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecEPSS 0.1%