VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 250 of 327
  • CVE-2022-39370MedNov 3, 2022
    risk 0.28cvss 4.3epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Connected users may gain access to debug panel through the GLPI update script. This…

  • CVE-2022-3030MedOct 17, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

  • CVE-2022-2630MedOct 17, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

  • CVE-2022-32226MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accepted by the server, so that instead of a matching rid String…

  • CVE-2022-34259MedAug 16, 2022
    risk 0.28cvss 5.3epss 0.02

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a…

  • CVE-2022-33924MedAug 10, 2022
    risk 0.28cvss 4.3epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules could potentially exploit this vulnerability and create rules.

  • CVE-2020-1754MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

  • CVE-2016-4426MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.

  • CVE-2022-32256MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.

  • CVE-2021-35249MedMay 17, 2022
    risk 0.28cvss 4.3epss 0.01

    This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a…

  • CVE-2022-29417MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.01

    Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.

  • CVE-2022-28777MedApr 11, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.

  • CVE-2021-45074MedMar 2, 2022
    risk 0.28cvss 4.3epss 0.01

    JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

  • CVE-2021-24688MedFeb 28, 2022
    risk 0.28cvss 4.3epss 0.00

    The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The…

  • CVE-2022-23981MedFeb 18, 2022
    risk 0.28cvss 4.3epss 0.01

    The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).

  • CVE-2022-23433MedFeb 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.

  • CVE-2022-23600MedFeb 4, 2022
    risk 0.28cvss 5.3epss 0.01

    fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1. A malicious or compromised Service…

  • CVE-2022-0203MedJan 26, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

  • CVE-2022-0179MedJan 12, 2022
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Missing Authorization

  • CVE-2021-24859MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including…