Fallos del tipo CWE-639

2498 resultados

Falsificação de referência direta a objeto (IDOR)

A aplicação não valida se o usuário tem permissão para acessar um recurso identificado por um parâmetro (como ID de usuário, pedido ou documento). Um atacante modifica esse parâmetro na URL ou requisição para acessar dados de outros usuários. É uma falha de autorização que confunde autenticação (saber quem você é) com controle de acesso (o que você pode ver).

Ejemplo

Um banco permite consultar extrato via URL /extrato?conta_id=12345. Um cliente autenticado muda conta_id para 12346 e acessa o extrato de outro cliente. A aplicação validou apenas se o usuário estava logado, não se tinha direito àquele extrato específico.

Cómo mitigar

Em cada requisição, verifique explicitamente se o usuário autenticado tem permissão para acessar aquele recurso específico (compare o ID solicitado com o contexto do usuário logado). Use IDs opacos/indiretos gerados pelo servidor em vez de sequências previsíveis, sempre como camada adicional, nunca como única proteção.

CVE-2025-10570MEDIUMFlexible Refund and Return Order for WooCommerce <= 1.0.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order RefundEPSS 0.2%CVE-2025-6833MEDIUMAll in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Clocking In/OutEPSS 0.2%CVE-2026-67358MEDIUMJoomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5EPSS 0.2%CVE-2026-16264MEDIUMNewsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOREPSS 0.2%CVE-2026-48073MEDIUMDocmost: Page export can include restricted same-space attachments through forged attachmentIdEPSS 0.2%CVE-2026-52850MEDIUMDocmost: Broken access control in transclusion lookup API leaks sync-block content across private spacesEPSS 0.2%CVE-2026-16567MEDIUMDocument Embedder < 2.3.1 - Unauthenticated Private Document Download via Token OracleEPSS 0.2%CVE-2026-13146LOWWP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOREPSS 0.2%CVE-2025-12766MEDIUMInsecure Direct Object Reference (IDOR) vulnerability in the Management Console of affected versions of BlackBerry AtHoc.EPSS 0.2%CVE-2025-65096MEDIUMRomM Insecure Direct Object Reference (IDOR) Allows Unauthorized Access to Private CollectionsEPSS 0.2%CVE-2026-1338MEDIUMAuthorization Bypass Through User-Controlled Key in GitLabEPSS 0.2%CVE-2024-1470HIGHElevation of Privilege attack on NetIQ Client login extensionEPSS 0.2%CVE-2026-93366MEDIUMBludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX EndpointsEPSS 0.2%CVE-2026-1228MEDIUMTimeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Private Timeline Exposure via Shortcode AttributeEPSS 0.2%CVE-2026-16281HIGHClassified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOREPSS 0.2%CVE-2025-61950MEDIUMIn GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. WEPSS 0.2%CVE-2026-88912MEDIUMrtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Privacy Modification via IDOREPSS 0.2%CVE-2025-12086MEDIUMReturn Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request CancellationEPSS 0.2%CVE-2026-81653MEDIUMNextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOREPSS 0.2%CVE-2025-12087MEDIUMWishlist and Save for later for Woocommerce <= 1.1.22 - Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item DeletionEPSS 0.2%