Falhas do tipo CWE-601

1.191 resultados

Redirecionamento aberto (Open Redirect)

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro, query string, etc.) sem validar se o destino é confiável. Um atacante controla para onde a vítima é levada, usando a reputação da aplicação legítima para enganá-la e roubar credenciais ou distribuir malware.

Exemplo

Um site de login tem `redirect.php?url=https://exemplo.com/dashboard`. O atacante muda para `redirect.php?url=https://site-falso.com` e envia o link falso por phishing. A vítima clica confiando no domínio legítimo e acaba em um site fake que coleta suas credenciais.

Como mitigar

Valide e whitelist as URLs permitidas antes de redirecionar — nunca confie no input do usuário. Alternativamente, use IDs ou tokens que mapeiem para destinos pré-aprovados, ou verifique se a URL pertence ao mesmo domínio (validação com regex ou parsing seguro da URL).

CVE-2025-59013MEDIUMOpen Redirect in TYPO3 CMSEPSS 0.2%CVE-2025-54088MEDIUMOpen Redirect in Secure Access prior to 14.10EPSS 0.2%CVE-2026-24847MEDIUMOpenEMR has Open Redirect in Eye Exam FormEPSS 0.2%CVE-2026-46894HIGHVulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affecteEPSS 0.2%CVE-2026-60648HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2025-1269MEDIUMOpen Redirect in HAVELSAN's Open Source Project Liman MYSEPSS 0.2%CVE-2026-1166MEDIUMOpen Redirect Vulnerability in Hitachi Ops Center AdministratorEPSS 0.2%CVE-2025-1885MEDIUMOpen Redirect in Restajet's Online Food Delivery SystemEPSS 0.2%CVE-2025-61166MEDIUMAn open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.EPSS 0.2%CVE-2026-60640HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-26483MEDIUMDell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially expEPSS 0.2%CVE-2025-9072HIGHOne-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterEPSS 0.2%CVE-2025-55060MEDIUMPriority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')EPSS 0.2%CVE-2025-11222MEDIUMCentral Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via sEPSS 0.2%CVE-2025-9084LOWOpen redirect in OAuth loginEPSS 0.2%CVE-2026-24328MEDIUMOpen Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)EPSS 0.2%CVE-2026-46955HIGHVulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected arEPSS 0.2%CVE-2024-34328MEDIUMAn open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.EPSS 0.2%CVE-2025-66447NONEChamilo LMS has validation-less redirect on login pageEPSS 0.2%CVE-2026-60658HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%