Fallos del tipo CWE-639

2497 resultados

Falsificação de referência direta a objeto (IDOR)

A aplicação não valida se o usuário tem permissão para acessar um recurso identificado por um parâmetro (como ID de usuário, pedido ou documento). Um atacante modifica esse parâmetro na URL ou requisição para acessar dados de outros usuários. É uma falha de autorização que confunde autenticação (saber quem você é) com controle de acesso (o que você pode ver).

Ejemplo

Um banco permite consultar extrato via URL /extrato?conta_id=12345. Um cliente autenticado muda conta_id para 12346 e acessa o extrato de outro cliente. A aplicação validou apenas se o usuário estava logado, não se tinha direito àquele extrato específico.

Cómo mitigar

Em cada requisição, verifique explicitamente se o usuário autenticado tem permissão para acessar aquele recurso específico (compare o ID solicitado com o contexto do usuário logado). Use IDs opacos/indiretos gerados pelo servidor em vez de sequências previsíveis, sempre como camada adicional, nunca como única proteção.

CVE-2026-80342MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order IDEPSS 0.2%CVE-2025-67594MEDIUMWordPress Thim Elementor Kit plugin <= 1.3.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-24776MEDIUMOpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transferEPSS 0.2%CVE-2025-61876MEDIUMInsecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user withEPSS 0.2%CVE-2026-48783MEDIUMPostiz has an unauthenticated billing-enforcement bypass via /public/modify-subscriptionEPSS 0.2%CVE-2026-11142MEDIUMInsufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via EPSS 0.2%CVE-2024-22439MEDIUMCertain HPE FlexNetwork and FlexFabric Switches, Remote Authentication BypassEPSS 0.2%CVE-2025-10912MEDIUMIDOR in saastech.io's TemizlikYoldaEPSS 0.2%CVE-2026-17627MEDIUMLangflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpointEPSS 0.2%CVE-2025-7733MEDIUMWP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object ReferenceEPSS 0.2%CVE-2026-55411MEDIUMToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secretsEPSS 0.2%CVE-2025-12126MEDIUMThe Total Book Project <= 1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Book ManipulationEPSS 0.2%CVE-2022-48313MEDIUMThe Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerabEPSS 0.2%CVE-2026-81339MEDIUMMasterStudy LMS < 3.7.50 - Subscriber+ Quiz Attempt Grade Disclosure via IDOREPSS 0.2%CVE-2026-77766MEDIUMDirectorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders EndpointEPSS 0.2%CVE-2026-1753MEDIUMGutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options UpdateEPSS 0.2%CVE-2026-22489MEDIUMWordPress Image Slider Slideshow plugin <= 1.8 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-2230MEDIUMBooking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings ModificationEPSS 0.2%CVE-2025-40773MEDIUMA vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access controEPSS 0.2%CVE-2025-12063MEDIUMAn insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissEPSS 0.2%