Fallos del tipo CWE-601

1191 resultados

Redirecionamento para URL não validada (Open Redirect)

A aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro GET/POST, referer, etc.) sem validar se o destino é confiável. Um atacante pode usar isso para levar vítimas a sites maliciosos, phishing ou roubo de credenciais, enquanto a URL legítima da sua app aparece no clique inicial.

Ejemplo

Um site de e-commerce redireciona após login com `redirect.php?url=google.com`. Um atacante envia `redirect.php?url=seusite-fake.com` disfarçado de e-mail de confirmação. A vítima clica, vê a URL legítima na barra de endereço até o redirecionamento, e cai em um fake convincente.

Cómo mitigar

Valide a URL de destino contra uma whitelist de domínios permitidos ou, no mínimo, verifique se o host da URL é o seu próprio domínio antes de redirecionar. Nunca redirecione para URLs externas fornecidas pelo usuário sem controle explícito.

CVE-2026-60685MEDIUMVulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecEPSS 0.1%CVE-2026-60957MEDIUMVulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.1%CVE-2026-60911MEDIUMVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.1%CVE-2026-62563MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2026-20994MEDIUMURL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.EPSS 0.1%CVE-2026-28631HIGHIn buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could leadEPSS 0.1%CVE-2026-28572HIGHIn onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation oEPSS 0.1%CVE-2026-28626HIGHIn onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could leEPSS 0.1%CVE-2026-28630LOWIn onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local infEPSS 0.1%CVE-2026-97165MEDIUMJoomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0EPSS —CVE-2026-101090CRITICALNezha through 2.2.3 Host Header Injection via OAuth2 redirect_uriEPSS —