Falhas do tipo CWE-840

99 resultados

Falhas na Lógica de Negócio

É quando o código implementa corretamente as instruções, mas essas instruções não refletem corretamente as regras de negócio pretendidas. O atacante explora desvios entre o que o sistema *deveria* fazer e o que ele realmente faz para contornar controles, contabilidade ou autorização.

Exemplo

Um carrinho de compras que permite aplica cupom de desconto múltiplas vezes quando deveria aceitar apenas uma; ou um sistema de transferência bancária que não valida se a conta de destino pertence ao mesmo titular, permitindo movimentações não autorizadas entre contas.

Como mitigar

Valide regras de negócio no backend (nunca confie no frontend). Implemente testes que cobram cenários de abuso: cupons reutilizados, limites ultrapassados, estados inválidos. Mantenha auditoria de operações sensíveis e revise regularmente a lógica com especialistas de negócio.

CVE-2025-2938LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2026-19993MEDIUMWebkul Bagisto RMA State Validation update-status behavioral workflowEPSS 0.3%CVE-2026-19208MEDIUMWonderTrader TraderDD.cpp queryTrades behavioral workflowEPSS 0.3%CVE-2026-75081MEDIUMWebkul Bagisto store behavioral workflowEPSS 0.3%CVE-2026-1600MEDIUMBdtask Bhojon All-In-One Restaurant Management System Add-to-Cart Submission Endpoint addtocart logic errorEPSS 0.3%CVE-2025-10868LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2026-82423MEDIUMmacrozheng mall Payment Status Endpoint paySuccess behavioral workflowEPSS 0.3%CVE-2026-5811MEDIUMSourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic errorEPSS 0.2%CVE-2024-1456HIGHS3 Bucket Takeover in h2oai/h2o-3EPSS 0.2%CVE-2026-5812MEDIUMSourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic errorEPSS 0.2%CVE-2026-79406MEDIUMmacrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic errorEPSS 0.2%CVE-2026-11465LOWsongquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic errorEPSS 0.2%CVE-2026-19037MEDIUMWonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflowEPSS 0.2%CVE-2026-19213MEDIUMWonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflowEPSS 0.2%CVE-2026-4547MEDIUMmickasmt next-saas-stripe-starter Checkout generate-user-stripe.ts generateUserStripe logic errorEPSS 0.2%CVE-2024-51523HIGHInformation management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidenEPSS 0.2%CVE-2026-77166LOWThe emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebarEPSS 0.2%CVE-2026-82982MEDIUMThe Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from appEPSS 0.2%CVE-2024-54098HIGHService logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service inteEPSS 0.2%CVE-2024-56449MEDIUMPrivilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.2%