VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 2 of 18
  • CVE-2025-34298HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state,…

  • CVE-2025-25711HigMar 12, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/admin/updateUser] API endpoint

  • CVE-2024-53355HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.01

    Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealias route; (4) delete…

  • CVE-2023-42228HigJan 13, 2025
    risk 0.57cvss 8.8epss 0.00

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.

  • CVE-2024-54818HigJan 8, 2025
    risk 0.57cvss 8.8epss 0.01

    SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.

  • CVE-2024-50930HigDec 10, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

  • CVE-2024-50920HigDec 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.

  • CVE-2023-44794CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

  • CVE-2023-41939HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.

  • CVE-2023-34672HigJun 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.

  • CVE-2023-28161HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.01

    If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dangerous if the local files came from…

  • CVE-2023-31923HigMay 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation,…

  • CVE-2020-36070CriApr 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.

  • CVE-2023-28668CriApr 2, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

  • CVE-2022-38473HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

  • CVE-2019-14841HigOct 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.

  • CVE-2022-38577HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.02

    ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

  • CVE-2022-22472HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper…

  • CVE-2021-45008HigFeb 21, 2022
    risk 0.57cvss 8.8epss 0.02

    Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

  • CVE-2020-8913HigAug 12, 2020
    risk 0.57cvss 8.8epss 0.03

    A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the…