Fallos del tipo CWE-841

56 resultados

Falha na Imposição de Fluxo de Trabalho Comportamental

É quando a aplicação não valida ou não obriga a sequência correta de operações que deveriam ocorrer em uma ordem específica. Um atacante consegue pular etapas, executar ações fora de ordem ou acessar funcionalidades que só deveriam estar disponíveis após certas condições serem atendidas, contornando a lógica de negócio esperada.

Ejemplo

Um sistema de checkout que deveria forçar: login → endereço → pagamento → confirmação. Se o desenvolvedor não validar o estado antes de cada etapa, um atacante pode pular direto para 'confirmação' sem pagar, ou acessar a página de pagamento sem ter preenchido endereço, comprometendo a integridade da transação.

Cómo mitigar

Implemente validação rigorosa de estado antes de cada operação sensível (verificar session, permissões, etapas anteriores completadas). Use máquinas de estado explícitas no backend e nunca confie em controles apenas no frontend; sempre reinforce no servidor qual é a próxima ação permitida.

CVE-2022-1667HIGHSecheron SEPCOS Control and Protection RelayEPSS 1.2%CVE-2023-4181MEDIUMSourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflowEPSS 1.1%CVE-2022-2105CRITICALSecheron SEPCOS Control and Protection RelayEPSS 1.0%CVE-2022-2102CRITICALSecheron SEPCOS Control and Protection RelayEPSS 0.9%CVE-2024-51738HIGHSunshine improperly enforces pairing protocol request orderEPSS 0.6%CVE-2024-37296MEDIUMAimeos HTML client vulnerable to digital products download without proper payment status checkEPSS 0.5%CVE-2025-55332MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-55330MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-6128MEDIUMspa-cartcms Checkout Page checkout behavioral workflowEPSS 0.5%CVE-2025-58051MEDIUMNextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a tableEPSS 0.5%CVE-2026-43937HIGHYAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via `/Admin/RunSql`EPSS 0.5%CVE-2025-55682MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-55337MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-46307HIGHA loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.EPSS 0.5%CVE-2024-0410HIGHImproper Enforcement of Behavioral Workflow in GitLabEPSS 0.5%CVE-2025-48481MEDIUMFreeScout Has Business Logic ErrorsEPSS 0.5%CVE-2025-48476HIGHFreeScout Has Business Logic ErrorsEPSS 0.4%CVE-2026-3130CRITICALImproper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perEPSS 0.4%CVE-2025-2323MEDIUM274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral workflowEPSS 0.4%CVE-2024-39325MEDIUMaimeos/ai-controller-frontend doesn't reset payment status in basketEPSS 0.4%