Falhas do tipo CWE-601

1.191 resultados

Redirecionamento aberto (Open Redirect)

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (parâmetro, query string, etc.) sem validar se o destino é confiável. Um atacante controla para onde a vítima é levada, usando a reputação da aplicação legítima para enganá-la e roubar credenciais ou distribuir malware.

Exemplo

Um site de login tem `redirect.php?url=https://exemplo.com/dashboard`. O atacante muda para `redirect.php?url=https://site-falso.com` e envia o link falso por phishing. A vítima clica confiando no domínio legítimo e acaba em um site fake que coleta suas credenciais.

Como mitigar

Valide e whitelist as URLs permitidas antes de redirecionar — nunca confie no input do usuário. Alternativamente, use IDs ou tokens que mapeiem para destinos pré-aprovados, ou verifique se a URL pertence ao mesmo domínio (validação com regex ou parsing seguro da URL).

CVE-2026-60685MEDIUMVulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecEPSS 0.1%CVE-2026-60957MEDIUMVulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.1%CVE-2026-60911MEDIUMVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.1%CVE-2026-62563MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2026-20994MEDIUMURL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.EPSS 0.1%CVE-2026-28631HIGHIn buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could leadEPSS 0.1%CVE-2026-28572HIGHIn onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation oEPSS 0.1%CVE-2026-28626HIGHIn onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could leEPSS 0.1%CVE-2026-28630LOWIn onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local infEPSS 0.1%CVE-2026-97165MEDIUMJoomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0EPSS —CVE-2026-101090CRITICALNezha through 2.2.3 Host Header Injection via OAuth2 redirect_uriEPSS —