Fallos del tipo CWE-73

671 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2025-62382HIGHFrigate Vulnerable to Arbitrary File Read via Export Thumbnail "image_path" parameterEPSS 0.3%CVE-2025-10306LOWBackup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File DownloadEPSS 0.3%CVE-2020-1984HIGHSecdo: Privilege escalation via hardcoded script pathEPSS 0.3%CVE-2026-1669HIGHArbitrary File Read in Keras via HDF5 External DatasetsEPSS 0.3%CVE-2021-22539HIGHCode execution in VSCode-bazel via malicious Bazel config filesEPSS 0.3%CVE-2025-0202MEDIUMTCS BaNCS REPORTS_SHOW_FILE.jsp file inclusionEPSS 0.3%CVE-2025-4674HIGHUnexpected command execution in untrusted VCS repositories in cmd/goEPSS 0.3%CVE-2026-10694MEDIUMSourceCodester Online Food Ordering System index.php include file inclusionEPSS 0.3%CVE-2019-25472HIGHIntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFileEPSS 0.3%CVE-2026-92595MEDIUMNodemailer before 9.1.1 Security Sandbox Bypass via resolveContentEPSS 0.3%CVE-2025-48067MEDIUMOctoPrint vulnerable to possible file extraction via upload endpointsEPSS 0.3%CVE-2025-8050MEDIUMExternal Control of File vulnerability has been discovered in opentext Flipper.EPSS 0.3%CVE-2025-8048MEDIUMExternal Control of File path vulnerability has been discovered on Openext Flipper.EPSS 0.3%CVE-2025-14059MEDIUMEmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path TraversalEPSS 0.3%CVE-2025-0898MEDIUMXpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVGEPSS 0.3%CVE-2026-2604MEDIUMEvolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handlingEPSS 0.3%CVE-2022-34669HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modiEPSS 0.3%CVE-2025-54780HIGHglpi-screenshot-plugin exposes local files in /ajax/screenshot.phpEPSS 0.3%CVE-2023-45588HIGHAn external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installEPSS 0.3%CVE-2025-61879HIGHIn Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.EPSS 0.3%