Falhas do tipo CWE-425

123 resultados

Validação inadequada de autorização em URLs e recursos restritos

A aplicação web falha em verificar se o usuário tem permissão para acessar URLs, scripts ou arquivos antes de entregá-los. Mesmo que o recurso seja 'restrito', qualquer usuário autenticado — ou até anônimo — consegue acessá-lo se souber a URL correta, contornando controles de acesso.

Exemplo

Um e-commerce permite que clientes logados acessem `/admin/relatorios/vendas` apenas mudando a URL no navegador, sem checagem real de permissão. Um usuário comum acessa dados financeiros ou relatórios confidenciais que deveriam estar bloqueados para ele.

Como mitigar

Implemente verificação de autorização em cada rota ou endpoint — não confie apenas em ocultação de links. Use um padrão consistente (ex: middleware de autorização) que valida o nível de permissão do usuário antes de servir qualquer recurso restrito. Sempre verifique permissões no servidor, nunca confie em controles apenas do lado do cliente.

CVE-2022-31484HIGHUser Account Deletion UnauthenticatedEPSS 1.0%CVE-2019-2388MEDIUMPotential exposure of log information in Ops ManagerEPSS 1.0%CVE-2024-24592CRITICALLack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily EPSS 1.0%CVE-2022-31480HIGHUnauthenticated Firmware Upload and Arbitrary RebootEPSS 0.9%CVE-2020-7541A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and ModiEPSS 0.9%CVE-2021-34588HIGHBender Charge Controller: Unprotected data exportEPSS 0.9%CVE-2022-2192HIGHForced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate EPSS 0.9%CVE-2022-42238HIGHA Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.EPSS 0.9%CVE-2024-7753MEDIUMSourceCodester Clinics Patient Management System user_images direct requestEPSS 0.9%CVE-2022-24385MEDIUMInformation disclosure via direct object access on SmarterTrack v100.0.8019.14010EPSS 0.9%CVE-2023-5786MEDIUMGeoServer GeoWebCache rest.html direct requestEPSS 0.8%CVE-2022-45276CRITICALAn issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account paEPSS 0.8%CVE-2022-31485MEDIUMUnauthenticated homepage note modificationEPSS 0.8%CVE-2026-0790MEDIUMALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-3792MEDIUMBeijing Netcon NS-ASG test_status.php direct requestEPSS 0.7%CVE-2025-6352MEDIUMcode-projects Automated Voting System Backend vote.php direct requestEPSS 0.7%CVE-2022-40845MEDIUMThe Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper autEPSS 0.7%CVE-2022-25626MEDIUMAn unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to cEPSS 0.7%CVE-2023-1682MEDIUMXunrui CMS Install.txt direct requestEPSS 0.7%CVE-2024-42001MEDIUMVonets WiFi Bridges Forced BrowsingEPSS 0.7%