Falhas do tipo CWE-601

1.187 resultados

Redirecionamento aberto (Open Redirect)

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro, query string, etc.) sem validar se o destino é confiável. Um atacante controla para onde a vítima é levada, usando a reputação da aplicação legítima para enganá-la e roubar credenciais ou distribuir malware.

Exemplo

Um site de login tem `redirect.php?url=https://exemplo.com/dashboard`. O atacante muda para `redirect.php?url=https://site-falso.com` e envia o link falso por phishing. A vítima clica confiando no domínio legítimo e acaba em um site fake que coleta suas credenciais.

Como mitigar

Valide e whitelist as URLs permitidas antes de redirecionar — nunca confie no input do usuário. Alternativamente, use IDs ou tokens que mapeiem para destinos pré-aprovados, ou verifique se a URL pertence ao mesmo domínio (validação com regex ou parsing seguro da URL).

CVE-2026-3049MEDIUMhorilla-opensource horilla Query Parameter global_search.py get redirectEPSS 0.4%CVE-2025-21512MEDIUMVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.4%CVE-2023-47779MEDIUMWordPress Integration for Contact Form 7 and Constant Contact Plugin <= 1.1.4 is vulnerable to Open RedirectionEPSS 0.4%CVE-2026-12049MEDIUMpgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameterEPSS 0.4%CVE-2024-32129MEDIUMWordPress Freshdesk (official) plugin <= 2.3.6 - Open Redirection vulnerabilityEPSS 0.4%CVE-2026-70958CRITICALVulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). TheEPSS 0.4%CVE-2021-25655MEDIUMURL redirection to untrusted site possible in Avaya Aura Experience PortalEPSS 0.4%CVE-2022-37927MEDIUMURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). EPSS 0.4%CVE-2024-20400MEDIUMA vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirectEPSS 0.4%CVE-2026-53573MEDIUMcore-geonetwork has an Open Redirect BypassEPSS 0.4%CVE-2025-0705MEDIUMJoeyBling bootplus QrCodeController.java qrCode redirectEPSS 0.4%CVE-2023-20264MEDIUMA vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco AEPSS 0.4%CVE-2024-0854MEDIUMURL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.EPSS 0.4%CVE-2024-31253MEDIUMWordPress WP OAuth Server (OAuth Authentication) plugin <= 4.3.3 - Open Redirection vulnerabilityEPSS 0.4%CVE-2024-34071MEDIUMOpen Redirect Bypass Protection EPSS 0.4%CVE-2023-32101MEDIUMWordPress Library Viewer Plugin <= 2.0.6 is vulnerable to Open RedirectionEPSS 0.4%CVE-2023-49394MEDIUMZentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.EPSS 0.4%CVE-2021-4260MEDIUMoils-js Web.js redirectEPSS 0.4%CVE-2026-47026HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions EPSS 0.4%CVE-2026-34931HIGHhoppscotch: Improper loopback redirect_uri validation in device-login flowEPSS 0.4%