CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 88 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4545 | Hig | 0.50 | 7.7 | 0.01 | May 14, 2024 | All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not… | ||
| CVE-2024-3507 | Hig | 0.50 | 7.7 | 0.00 | May 8, 2024 | Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerability allows an attacker to perform a secondary process injection into the Lunar application and abuse those rights to access sensitive user information. | ||
| CVE-2024-32003 | Hig | 0.50 | 8.8 | 0.01 | Apr 12, 2024 | wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User… | ||
| CVE-2024-1505 | Hig | 0.50 | 8.8 | 0.01 | Mar 13, 2024 | The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This… | ||
| CVE-2023-36496 | Hig | 0.50 | 7.7 | 0.01 | Feb 1, 2024 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | ||
| CVE-2023-4697 | Hig | 0.50 | 8.8 | 0.01 | Sep 1, 2023 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2023-3636 | Hig | 0.50 | 8.8 | 0.01 | Aug 31, 2023 | The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a… | ||
| CVE-2023-0872 | Hig | 0.50 | 8.2 | 0.03 | Aug 14, 2023 | The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer.… | ||
| CVE-2023-4293 | Hig | 0.50 | 8.8 | 0.01 | Aug 12, 2023 | The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers,… | ||
| CVE-2023-2240 | Hig | 0.50 | 8.8 | 0.01 | Apr 22, 2023 | Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. | ||
| CVE-2023-1762 | Hig | 0.50 | 8.8 | 0.01 | Mar 31, 2023 | Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | ||
| CVE-2022-42735 | Hig | 0.50 | 8.8 | 0.01 | Feb 15, 2023 | Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.5.0. Upgrade to Apache ShenYu 2.5.1 or… | ||
| CVE-2022-4808 | Hig | 0.50 | 8.8 | 0.00 | Dec 28, 2022 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-38060 | Hig | 0.50 | 8.8 | 0.00 | Dec 21, 2022 | A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges. | ||
| CVE-2022-39286 | Hig | 0.50 | 8.8 | 0.01 | Oct 26, 2022 | Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows… | ||
| CVE-2022-2249 | Hig | 0.50 | 7.7 | 0.00 | Oct 12, 2022 | Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0. | ||
| CVE-2022-2975 | Hig | 0.50 | 7.7 | 0.00 | Oct 6, 2022 | A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services… | ||
| CVE-2022-3068 | Hig | 0.50 | 8.8 | 0.00 | Sep 21, 2022 | Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3. | ||
| CVE-2022-36157 | Hig | 0.50 | 8.8 | 0.01 | Aug 19, 2022 | XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account. | ||
| CVE-2022-26113 | Hig | 0.50 | 7.7 | 0.00 | Jul 19, 2022 | An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system. |
- risk 0.50cvss 7.7epss 0.01
All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not…
- risk 0.50cvss 7.7epss 0.00
Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerability allows an attacker to perform a secondary process injection into the Lunar application and abuse those rights to access sensitive user information.
- risk 0.50cvss 8.8epss 0.01
wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User…
- risk 0.50cvss 8.8epss 0.01
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This…
- risk 0.50cvss 7.7epss 0.01
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.50cvss 8.8epss 0.01
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a…
- risk 0.50cvss 8.2epss 0.03
The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer.…
- risk 0.50cvss 8.8epss 0.01
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers,…
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.5.0. Upgrade to Apache ShenYu 2.5.1 or…
- risk 0.50cvss 8.8epss 0.00
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.00
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
- risk 0.50cvss 8.8epss 0.01
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows…
- risk 0.50cvss 7.7epss 0.00
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.
- risk 0.50cvss 7.7epss 0.00
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services…
- risk 0.50cvss 8.8epss 0.00
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
- risk 0.50cvss 8.8epss 0.01
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
- risk 0.50cvss 7.7epss 0.00
An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.