VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 21 of 404
  • CVE-2024-37566CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.00

    Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.

  • CVE-2024-53573CriFeb 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.

  • CVE-2025-26617CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26613CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.03

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, `gerenciar_backup.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code…

  • CVE-2025-26611CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26609CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26608CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26607CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `documento_excluir.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26606CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `informacao_adicional.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2024-39327CriFeb 18, 2025
    risk 0.64cvss 9.9epss 0.00

    Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

  • CVE-2024-57032CriJan 17, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

  • CVE-2023-26770CriOct 4, 2024
    risk 0.64cvss 9.8epss 0.01

    TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

  • CVE-2024-42797CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.

  • CVE-2024-45489CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the…

  • CVE-2023-37234CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Loftware Spectrum through 4.6 has unprotected JMX Registry.

  • CVE-2024-36068CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.00

    An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.

  • CVE-2024-42919CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

  • CVE-2024-42559CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.

  • CVE-2024-42967CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

  • CVE-2024-40480CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access.