Falhas do tipo CWE-73
668 resultadosControle de acesso inadequado
A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.
Exemplo
Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.
Como mitigar
Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.
CVE-2023-35985HIGHAn arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to propEPSS 2.7%CVE-2022-28710MEDIUMAn information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speciallEPSS 2.7%CVE-2025-59516HIGHWindows Storage VSP Driver Elevation of Privilege VulnerabilityEPSS 2.3%CVE-2014-2375—Ecava IntegraXor SCADA Server External Control of File Name or PathEPSS 2.3%CVE-2018-14820—Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, whichEPSS 2.2%CVE-2025-68428CRITICALjsPDF has Local File Inclusion/Path Traversal vulnerabilityEPSS 2.2%CVE-2018-7495—In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 2.2%CVE-2023-36764HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 2.1%CVE-2020-6105HIGHAn exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted fEPSS 2.1%CVE-2024-20652HIGHWindows HTML Platforms Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2024-5334HIGHLocal File Read in stitionai/devikaEPSS 2.1%CVE-2023-40194HIGHAn arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of wEPSS 2.0%CVE-2025-0111HIGHPAN-OS: Authenticated File Read Vulnerability in the Management Web InterfaceEPSS 2.0%KEVCVE-2020-2009HIGHPAN-OS: Panorama SD WAN arbitrary file creationEPSS 2.0%CVE-2025-59049HIGHMockoon has a Path Traversal and LFI in the static file serving endpointEPSS 1.8%CVE-2023-46851—Apache Allura: sensitive information exposure via importEPSS 1.6%CVE-2024-38657CRITICALExternal control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a rEPSS 1.6%CVE-2025-71324HIGHFlowise - Arbitrary File Read via chatId ParameterEPSS 1.6%CVE-2020-25161—The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operatioEPSS 1.6%CVE-2023-35384MEDIUMWindows HTML Platforms Security Feature Bypass VulnerabilityEPSS 1.6%