Fallos del tipo CWE-639

2494 resultados

Falsificação de referência direta a objeto (IDOR)

A aplicação não valida se o usuário tem permissão para acessar um recurso identificado por um parâmetro (como ID de usuário, pedido ou documento). Um atacante modifica esse parâmetro na URL ou requisição para acessar dados de outros usuários. É uma falha de autorização que confunde autenticação (saber quem você é) com controle de acesso (o que você pode ver).

Ejemplo

Um banco permite consultar extrato via URL /extrato?conta_id=12345. Um cliente autenticado muda conta_id para 12346 e acessa o extrato de outro cliente. A aplicação validou apenas se o usuário estava logado, não se tinha direito àquele extrato específico.

Cómo mitigar

Em cada requisição, verifique explicitamente se o usuário autenticado tem permissão para acessar aquele recurso específico (compare o ID solicitado com o contexto do usuário logado). Use IDs opacos/indiretos gerados pelo servidor em vez de sequências previsíveis, sempre como camada adicional, nunca como única proteção.

CVE-2025-59133HIGHWordPress Projectopia plugin <= 5.1.25.2 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-31832MEDIUMUmbraco Backoffice API Allows Unauthorized Modification of Domain DataEPSS 0.3%CVE-2026-12697MEDIUMwpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOREPSS 0.3%CVE-2025-62244MEDIUMInsecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 tEPSS 0.3%CVE-2026-45385MEDIUMOpen WebUI: An IDOR vulnerability exists in the update_message_by_id API endpointEPSS 0.3%CVE-2026-45386MEDIUMOpen WebUI: An IDOR vulnerability exists in the pin_channel_message API endpointEPSS 0.3%CVE-2026-28782MEDIUMCraft has a Permission Bypass and IDOR in Duplicate Entry ActionEPSS 0.3%CVE-2025-65030HIGHRallly Improper Authorization in Comment Deletion Endpoint Allows Unauthorized Comment RemovalEPSS 0.3%CVE-2025-12524MEDIUMPost Type Switcher <= 4.0.0 - Insecure Direct Object Reference to Authenticated (Author+) Post Type ChangeEPSS 0.3%CVE-2025-0661MEDIUMDethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post DisclosureEPSS 0.3%CVE-2024-13740MEDIUMProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages DisclosureEPSS 0.3%CVE-2026-10038MEDIUMCharitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' ParameterEPSS 0.3%CVE-2026-44585MEDIUMPaymenter: Broken object level authorization via service reference manipulation on ticket creationEPSS 0.3%CVE-2025-9342MEDIUMIDOR in Anadolu Hayat Emeklilik's AHE MobileEPSS 0.3%CVE-2025-6574HIGHService Finder Bookings < 6.1 - Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.3%CVE-2025-13389MEDIUMAdmin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated Information DisclosureEPSS 0.3%CVE-2026-35023MEDIUMWimi Teamwork On-Premises < 8.2.0 IDOR via preview.phpEPSS 0.3%CVE-2025-8057MEDIUMIDOR in Patika Global Technologies' HumanSuiteEPSS 0.3%CVE-2025-34438MEDIUMAVideo < 20.1 IDOR Arbitrary Video RotationEPSS 0.3%CVE-2024-8988MEDIUMPeepSo Core: File Uploads <= 6.4.6.0 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via file_downloadEPSS 0.3%