Falhas do tipo CWE-601

1.191 resultados

Redirecionamento aberto (Open Redirect)

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro, query string, etc.) sem validar se o destino é confiável. Um atacante controla para onde a vítima é levada, usando a reputação da aplicação legítima para enganá-la e roubar credenciais ou distribuir malware.

Exemplo

Um site de login tem `redirect.php?url=https://exemplo.com/dashboard`. O atacante muda para `redirect.php?url=https://site-falso.com` e envia o link falso por phishing. A vítima clica confiando no domínio legítimo e acaba em um site fake que coleta suas credenciais.

Como mitigar

Valide e whitelist as URLs permitidas antes de redirecionar — nunca confie no input do usuário. Alternativamente, use IDs ou tokens que mapeiem para destinos pré-aprovados, ou verifique se a URL pertence ao mesmo domínio (validação com regex ou parsing seguro da URL).

CVE-2026-47002MEDIUMVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versEPSS 0.2%CVE-2026-34283MEDIUMVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that areEPSS 0.2%CVE-2026-62444MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2024-4604MEDIUMOpen Redirect in Magarsus Consultancy's SSOEPSS 0.2%CVE-2026-17912MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigationEPSS 0.2%CVE-2025-8129MEDIUMKoaJS Koa HTTP Header response.js back redirectEPSS 0.2%CVE-2024-55892MEDIUMPotential Open Redirect via Parsing Differences in TYPO3EPSS 0.2%CVE-2024-21734LOWURL Redirection vulnerability in SAP Marketing (Contacts App)EPSS 0.2%CVE-2026-40096MEDIUMimmich: Open Redirect via Shared Album nameEPSS 0.2%CVE-2024-45082MEDIUMIBM Cognos Analytics HTTP open redirectionEPSS 0.2%CVE-2026-47015HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported versioEPSS 0.2%CVE-2025-24741MEDIUMWordPress KB Support plugin <= 1.6.7 - Open Redirection vulnerabilityEPSS 0.2%CVE-2025-52219MEDIUMSelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to cEPSS 0.2%CVE-2024-45247MEDIUMSonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')EPSS 0.2%CVE-2025-57821MEDIUMBasecamp's Google Sign-In for Rails allowed redirects to a malformed URLEPSS 0.2%CVE-2026-47887MEDIUMSpring Framework Open Redirect in UrlFileNameViewControllerEPSS 0.2%CVE-2025-67852LOWMoodle: moodle: open redirect vulnerability in oauth login flow allows redirection to malicious sites.EPSS 0.2%CVE-2024-36419MEDIUMSuiteCRM-Core Host Header Injection in /legacy EPSS 0.2%CVE-2026-42207MEDIUMMagento LTS: Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` - magento-ltsEPSS 0.2%CVE-2026-8284MEDIUMOpen Redirect in Universal Sotware's FlexCityEPSS 0.2%