Fallos del tipo CWE-841

75 resultados

Falha na Imposição de Fluxo de Trabalho Comportamental

É quando a aplicação não valida ou não obriga a sequência correta de operações que deveriam ocorrer em uma ordem específica. Um atacante consegue pular etapas, executar ações fora de ordem ou acessar funcionalidades que só deveriam estar disponíveis após certas condições serem atendidas, contornando a lógica de negócio esperada.

Ejemplo

Um sistema de checkout que deveria forçar: login → endereço → pagamento → confirmação. Se o desenvolvedor não validar o estado antes de cada etapa, um atacante pode pular direto para 'confirmação' sem pagar, ou acessar a página de pagamento sem ter preenchido endereço, comprometendo a integridade da transação.

Cómo mitigar

Implemente validação rigorosa de estado antes de cada operação sensível (verificar session, permissões, etapas anteriores completadas). Use máquinas de estado explícitas no backend e nunca confie em controles apenas no frontend; sempre reinforce no servidor qual é a próxima ação permitida.

CVE-2026-53637MEDIUMSylius: Cart FormComponent allows modification or deletion of an already-completed orderEPSS 0.3%CVE-2026-78103MEDIUMDimension Log Server Configuration Lock Bypass VulnerabilityEPSS 0.3%CVE-2025-52469HIGHChamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation BypassEPSS 0.3%CVE-2025-36333MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.3%CVE-2026-19993MEDIUMWebkul Bagisto RMA State Validation update-status behavioral workflowEPSS 0.3%CVE-2026-80195HIGHKimai before 2.63.0 Team Membership Removal via APIEPSS 0.3%CVE-2023-1383MEDIUMAn Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attaEPSS 0.3%CVE-2026-19208MEDIUMWonderTrader TraderDD.cpp queryTrades behavioral workflowEPSS 0.3%CVE-2026-75081MEDIUMWebkul Bagisto store behavioral workflowEPSS 0.3%CVE-2026-79083HIGHImproper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-46540MEDIUMNimiq light-blockchain: Light blockchain rebranch issueEPSS 0.3%CVE-2026-30574HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application faEPSS 0.3%CVE-2026-78618MEDIUMDimension Business Logic Flaw Allows Chained Backend Object OperationsEPSS 0.3%CVE-2026-87503MEDIUMInappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social EPSS 0.3%CVE-2026-82423MEDIUMmacrozheng mall Payment Status Endpoint paySuccess behavioral workflowEPSS 0.3%CVE-2026-8477LOWImproper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticateEPSS 0.2%CVE-2023-5921HIGHFunction Bypass in GeodiEPSS 0.2%CVE-2025-48376LOWDnn.Platform's Site Import could use an external source with a crafted requestEPSS 0.2%CVE-2026-34582HIGHBotan has a TLS 1.3 certificate authentication bypassEPSS 0.2%CVE-2024-44128MEDIUMThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS EPSS 0.2%