Fallos del tipo CWE-425

117 resultados

Falta de validação de autorização em URLs, scripts ou arquivos restritos

A aplicação web não verifica adequadamente se o usuário tem permissão para acessar determinadas URLs, scripts ou arquivos antes de conceder o acesso. Um atacante consegue burlar os controles de autorização e acessar recursos que deveriam estar protegidos, como páginas administrativas, arquivos de configuração ou funcionalidades restritas.

Ejemplo

Um sistema bancário permite acesso à página de transferências via URL direta (/admin/transferir) apenas verificando se o usuário está logado, mas não confere se ele é administrador. Um usuário comum descobre a URL e transfere dinheiro sem autorização.

Cómo mitigar

Implemente verificação de autorização explícita em cada endpoint ou recurso restrito, não apenas autenticação. Use um padrão como controle de acesso baseado em papéis (RBAC) ou atributos (ABAC), centralizando a lógica de permissões e testando-a sistematicamente para todas as rotas sensíveis.

CVE-2023-44320MEDIUMA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAEPSS 0.6%CVE-2023-46186MEDIUMIBM Jazz for Service Management information disclosureEPSS 0.6%CVE-2024-6414MEDIUMParsec Automation TrakSYS Export Page contentpage direct requestEPSS 0.6%CVE-2025-2147MEDIUMBeijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System file accessEPSS 0.6%CVE-2023-3426MEDIUMThe organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permissiEPSS 0.6%CVE-2025-6352MEDIUMcode-projects Automated Voting System Backend vote.php direct requestEPSS 0.6%CVE-2022-42197MEDIUMIn Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modifyEPSS 0.6%CVE-2024-55075MEDIUMGrocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such EPSS 0.5%CVE-2026-42297HIGHArgo Workflows Is Missing Authorization in Sync ConfigMap ProviderEPSS 0.5%CVE-2024-2730MEDIUMPredictable Page Indexing Might Lead to Sensitive Data Exposure in MauticEPSS 0.5%CVE-2022-47700HIGHCOMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect AcceEPSS 0.5%CVE-2023-28160MEDIUMWhen following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking poEPSS 0.5%CVE-2026-0650CRITICALOpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path NormalizationEPSS 0.5%CVE-2024-7153MEDIUMNetgear WN604 siteSurvey.php direct requestEPSS 0.5%CVE-2024-0456MEDIUMDirect Request ('Forced Browsing') in GitLabEPSS 0.5%CVE-2023-45598MEDIUMA CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthentEPSS 0.5%CVE-2023-45596MEDIUMA CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remotEPSS 0.5%CVE-2026-22732CRITICALUnder Some Conditions Spring Security HTTP Headers Are not WrittenEPSS 0.5%CVE-2023-45809LOWDisclosure of user names via admin bulk action views in wagtailEPSS 0.5%CVE-2026-4532MEDIUMcode-projects Simple Food Ordering System Database Backup food.sql file accessEPSS 0.5%