VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 248 of 327
  • CVE-2023-6202MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.

  • CVE-2023-47865MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a…

  • CVE-2023-5916MedNov 2, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /config-manager/save of the component Configuration Handler. The manipulation of the argument config leads to improper access controls. It is possible to…

  • CVE-2023-41882MedOct 11, 2023
    risk 0.28cvss 5.4epss 0.00

    vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However,…

  • CVE-2023-36638MedSep 13, 2023
    risk 0.28cvss 4.3epss 0.00

    An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all…

  • CVE-2023-39973MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

  • CVE-2023-39972MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.

  • CVE-2023-20237MedAug 16, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker…

  • CVE-2023-4183MedAug 6, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the argument user_id leads to improper…

  • CVE-2023-3786MedJul 20, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of the component Kiosk Mode. The manipulation leads to improper access controls. It is possible to launch the attack on the physical device. The exploit has been…

  • CVE-2023-3431MedJun 27, 2023
    risk 0.28cvss 5.3epss 0.01

    Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.

  • CVE-2023-3304MedJun 23, 2023
    risk 0.28cvss 5.4epss 0.00

    Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

  • CVE-2023-2159MedJun 9, 2023
    risk 0.28cvss 5.3epss 0.01

    The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site…

  • CVE-2021-4364MedJun 7, 2023
    risk 0.28cvss 4.3epss 0.01

    The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add…

  • CVE-2020-36699MedJun 7, 2023
    risk 0.28cvss 4.3epss 0.01

    The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for…

  • CVE-2023-2903MedMay 25, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an unknown part of the file /SystemManage/Role/GetGridJson?keyword=&page=1&rows=20. The manipulation leads to improper access controls. It is possible to initiate…

  • CVE-2023-2902MedMay 25, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=1681813520783&rows=10000&page=1&sidx=&sord=asc. The…

  • CVE-2023-2901MedMay 25, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /SystemManage/User/GetGridJson?_search=false&nd=1680855479750&rows=50&page=1&sidx=F_CreatorTime+desc…

  • CVE-2021-44465MedApr 25, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.

  • CVE-2023-2104MedApr 15, 2023
    risk 0.28cvss 5.4epss 0.00

    Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.