Fallos del tipo CWE-451

346 resultados

Representação enganosa de informações críticas na interface

A aplicação apresenta informações de segurança ou avisos críticos de forma desorientadora, oculta ou disfarçada na UI, levando o usuário a tomar decisões perigosas sem compreender as consequências reais. O atacante explora isso para contornar decisões conscientes do usuário, como consentir a execução de código malicioso ou compartilhar dados sensíveis.

Ejemplo

Um navegador que exibe um aviso de certificado inválido em texto pequeno e cinzento no rodapé da página, enquanto mantém o resto do site completamente funcional e destacado, fazendo o usuário ignorar o risco e prosseguir. Ou um app que solicita permissão de câmera com a frase 'Necessário para melhor experiência' escondida em letras minúsculas, sem deixar claro que gravará vídeo.

Cómo mitigar

Deixe avisos e informações críticas de segurança visíveis, legíveis e sem ambiguidade: use cores de contraste alto, fonte adequada, posicionamento central, e linguagem clara. Exija confirmação explícita do usuário antes de ações perigosas e mostre exatamente o que será feito — nunca ocultando ou minimizando os riscos na apresentação.

CVE-2025-21404MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 1.0%CVE-2021-22866UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to user resourcesEPSS 1.0%CVE-2020-7370MEDIUMDanyil Vasilenko Bolt Browser Address Bar SpooofingEPSS 1.0%CVE-2020-7369MEDIUMYandex Browser Address Bar SpooofingEPSS 1.0%CVE-2020-7371MEDIUMRaise IT Solutions RITS Browser Address Bar SpooofingEPSS 1.0%CVE-2024-4950MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage iEPSS 0.9%CVE-2023-2937MEDIUMInappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised theEPSS 0.9%CVE-2023-2938MEDIUMInappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised theEPSS 0.9%CVE-2025-43228MEDIUMThe issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may leaEPSS 0.9%CVE-2024-0750HIGHA bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vEPSS 0.8%CVE-2025-29825MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.8%CVE-2025-64667MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 0.8%CVE-2022-34479MEDIUMA malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potEPSS 0.7%CVE-2020-7364MEDIUMUCWeb UC Browser Address Bar SpooofingEPSS 0.7%CVE-2020-7363MEDIUMUCWeb UC Browser Address Bar SpooofingEPSS 0.7%CVE-2021-33593Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may EPSS 0.7%CVE-2023-0700MEDIUMInappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contentsEPSS 0.7%CVE-2022-39258HIGHmailcow-dockerized critical information misrepresentation can lead to phishing attacks through Swagger UIEPSS 0.7%CVE-2022-26383MEDIUMWhen resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affectEPSS 0.7%CVE-2024-2631MEDIUMInappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 0.6%