Falhas do tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.

Exemplo

Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.

CVE-2023-47171MEDIUMAn information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev masterEPSS 1.1%CVE-2023-49862MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2023-49864MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2023-49863MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2026-11527HIGHConfig::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandleEPSS 1.1%CVE-2023-47862CRITICALA local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A speciEPSS 1.1%CVE-2023-21800HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2025-29819MEDIUMWindows Admin Center in Azure Portal Information Disclosure VulnerabilityEPSS 1.1%CVE-2026-30940HIGHbaserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCEEPSS 1.0%CVE-2020-2504MEDIUMAbsolute path traversal vulnerability in QESEPSS 1.0%CVE-2026-6101HIGHAMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font UploadEPSS 1.0%CVE-2024-41183HIGHTrend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevatioEPSS 1.0%CVE-2025-6691HIGHSureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionEPSS 1.0%CVE-2026-4132HIGHHTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' ParametersEPSS 1.0%CVE-2026-48749CRITICALIncus has an arbitrary file read+write on host via rootfs/ symlink in malicious imageEPSS 1.0%CVE-2024-4818MEDIUMCampcodes Online Laundry Management System index.php file inclusionEPSS 1.0%CVE-2023-4749MEDIUMSourceCodester Inventory Management System index.php file inclusionEPSS 1.0%CVE-2024-12875MEDIUMEasy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File DownloadEPSS 1.0%CVE-2026-54629HIGHAnyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeEPSS 1.0%CVE-2022-43513HIGHA vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 EPSS 1.0%