Fallos del tipo CWE-840

99 resultados

Erros de Lógica de Negócio

É quando o código implementa corretamente a sintaxe, mas a lógica por trás não reflete as regras de negócio esperadas — permitindo operações que deveriam ser bloqueadas ou produzindo resultados incorretos. O atacante explora brechas nessas regras para contornar controles, duplicar recursos, ou chegar a estados inválidos.

Ejemplo

Um e-commerce que valida se o preço é positivo, mas não valida se o desconto pode ser maior que o preço final, permitindo que o cliente pague valor negativo. Ou um sistema que transfere saldo entre contas sem verificar se o saldo é suficiente antes de débito.

Cómo mitigar

Defina explicitamente as regras de negócio (pré e pós-condições), documente-as e implemente testes automatizados que cobram cada cenário — incluindo casos extremos e cenários de ataque. Revise a lógica de autenticação, autorização e transações críticas com produto e segurança.

CVE-2025-2938LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2026-19993MEDIUMWebkul Bagisto RMA State Validation update-status behavioral workflowEPSS 0.3%CVE-2026-19208MEDIUMWonderTrader TraderDD.cpp queryTrades behavioral workflowEPSS 0.3%CVE-2026-75081MEDIUMWebkul Bagisto store behavioral workflowEPSS 0.3%CVE-2026-1600MEDIUMBdtask Bhojon All-In-One Restaurant Management System Add-to-Cart Submission Endpoint addtocart logic errorEPSS 0.3%CVE-2025-10868LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2026-82423MEDIUMmacrozheng mall Payment Status Endpoint paySuccess behavioral workflowEPSS 0.3%CVE-2026-5811MEDIUMSourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic errorEPSS 0.2%CVE-2024-1456HIGHS3 Bucket Takeover in h2oai/h2o-3EPSS 0.2%CVE-2026-5812MEDIUMSourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic errorEPSS 0.2%CVE-2026-79406MEDIUMmacrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic errorEPSS 0.2%CVE-2026-11465LOWsongquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic errorEPSS 0.2%CVE-2026-19037MEDIUMWonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflowEPSS 0.2%CVE-2026-19213MEDIUMWonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflowEPSS 0.2%CVE-2026-4547MEDIUMmickasmt next-saas-stripe-starter Checkout generate-user-stripe.ts generateUserStripe logic errorEPSS 0.2%CVE-2024-51523HIGHInformation management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidenEPSS 0.2%CVE-2026-77166LOWThe emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebarEPSS 0.2%CVE-2026-82982MEDIUMThe Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from appEPSS 0.2%CVE-2024-54098HIGHService logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service inteEPSS 0.2%CVE-2024-56449MEDIUMPrivilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.2%