Falhas do tipo CWE-601

1.191 resultados

Redirecionamento aberto (Open Redirect)

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro, query string, etc.) sem validar se o destino é confiável. Um atacante controla para onde a vítima é levada, usando a reputação da aplicação legítima para enganá-la e roubar credenciais ou distribuir malware.

Exemplo

Um site de login tem `redirect.php?url=https://exemplo.com/dashboard`. O atacante muda para `redirect.php?url=https://site-falso.com` e envia o link falso por phishing. A vítima clica confiando no domínio legítimo e acaba em um site fake que coleta suas credenciais.

Como mitigar

Valide e whitelist as URLs permitidas antes de redirecionar — nunca confie no input do usuário. Alternativamente, use IDs ou tokens que mapeiem para destinos pré-aprovados, ou verifique se a URL pertence ao mesmo domínio (validação com regex ou parsing seguro da URL).

CVE-2024-7312HIGHREST Interface Link Redirection via Host parameterEPSS 0.2%CVE-2025-23183MEDIUMUBtech – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')EPSS 0.2%CVE-2025-52897MEDIUMGLPI is vulnerable to XSS and open redirection attacks through planning featureEPSS 0.2%CVE-2026-24323MEDIUMMultiple vulnerabilities in BSP Applications of SAP Document Management SystemEPSS 0.2%CVE-2026-60636HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60664HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-42981MEDIUMMultiple vulnerabilities in SAP NetWeaver Application Server ABAPEPSS 0.2%CVE-2026-60634HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60639HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60637HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60635HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60638HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60633HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-63828MEDIUMHost Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leadinEPSS 0.2%CVE-2025-62266MEDIUMBy default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 tEPSS 0.2%CVE-2025-35059MEDIUMNewforma Info Exchange (NIX) open URL redirect via /DownloadWeb/hyperlinkredirect.aspxEPSS 0.2%CVE-2025-3027MEDIUMOpen Redirect vulnerability in EJBCAEPSS 0.2%CVE-2025-11167MEDIUMCM Registration – Tailored tool for seamless login and invitation-based registrations <= 2.5.6 - Open RedirectEPSS 0.2%CVE-2025-50736MEDIUMAn open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to reEPSS 0.2%CVE-2025-7777MEDIUMMirror-registry: host header injection in mirror-registryEPSS 0.2%