VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 143 of 186
  • CVE-2024-0674MedJan 30, 2024
    risk 0.41cvss 6.3epss 0.00

    Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause…

  • CVE-2023-20274MedNov 21, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient permissions that are set by the PHP Agent Installer on the PHP Agent…

  • CVE-2023-23629MedJan 28, 2023
    risk 0.41cvss 6.3epss 0.00

    Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone with greater access to data…

  • CVE-2022-4281MedDec 5, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads to authorization bypass. The attack can…

  • CVE-2021-43076MedSep 6, 2022
    risk 0.41cvss 6.3epss 0.01

    An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system files using the shell…

  • CVE-2019-25071MedJun 25, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit…

  • CVE-2017-20081MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/reports.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2017-20080MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The…

  • CVE-2017-20079MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has…

  • CVE-2017-20078MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/featured.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2017-20077MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown processing of the file /admin/success_story.php. The manipulation leads to improper privilege management. The attack may be initiated remotely. The exploit has…

  • CVE-2017-20076MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. This vulnerability affects unknown code of the file /admin/searchview.php. The manipulation leads to improper privilege management. The attack can be initiated remotely. The exploit has been…

  • CVE-2017-20075MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part of the file /admin/payment.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2017-20074MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit…

  • CVE-2017-20073MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cms.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit…

  • CVE-2017-20072MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/generalsettings.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit…

  • CVE-2017-20071MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. This issue affects some unknown processing of the file /admin/renewaldue.php. The manipulation leads to improper privilege management. The attack may be initiated remotely. The exploit…

  • CVE-2017-20070MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Hindu Matrimonial Script. This vulnerability affects unknown code of the file /admin/communitymanagement.php. The manipulation leads to improper privilege management. The attack can be initiated remotely. The exploit has been…

  • CVE-2017-20069MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/countrymanagement.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2017-20068MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/usermanagement.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The…