Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2023-35985HIGHAn arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to propEPSS 2.7%CVE-2022-28710MEDIUMAn information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speciallEPSS 2.7%CVE-2025-59516HIGHWindows Storage VSP Driver Elevation of Privilege VulnerabilityEPSS 2.3%CVE-2014-2375—Ecava IntegraXor SCADA Server External Control of File Name or PathEPSS 2.3%CVE-2018-14820—Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, whichEPSS 2.2%CVE-2025-68428CRITICALjsPDF has Local File Inclusion/Path Traversal vulnerabilityEPSS 2.2%CVE-2018-7495—In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 2.2%CVE-2023-36764HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 2.1%CVE-2020-6105HIGHAn exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted fEPSS 2.1%CVE-2024-20652HIGHWindows HTML Platforms Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2024-5334HIGHLocal File Read in stitionai/devikaEPSS 2.1%CVE-2023-40194HIGHAn arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of wEPSS 2.0%CVE-2025-0111HIGHPAN-OS: Authenticated File Read Vulnerability in the Management Web InterfaceEPSS 2.0%KEVCVE-2020-2009HIGHPAN-OS: Panorama SD WAN arbitrary file creationEPSS 2.0%CVE-2025-59049HIGHMockoon has a Path Traversal and LFI in the static file serving endpointEPSS 1.8%CVE-2023-46851—Apache Allura: sensitive information exposure via importEPSS 1.6%CVE-2024-38657CRITICALExternal control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a rEPSS 1.6%CVE-2025-71324HIGHFlowise - Arbitrary File Read via chatId ParameterEPSS 1.6%CVE-2020-25161—The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operatioEPSS 1.6%CVE-2023-35384MEDIUMWindows HTML Platforms Security Feature Bypass VulnerabilityEPSS 1.6%