VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 251 of 327
  • CVE-2021-42116MedNov 30, 2021
    risk 0.28cvss 4.3epss 0.01

    Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users, via identifying said…

  • CVE-2021-24853MedNov 17, 2021
    risk 0.28cvss 4.3epss 0.00

    The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary…

  • CVE-2021-24816MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.01

    The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.

  • CVE-2021-24801MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.00

    The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to…

  • CVE-2021-24698MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

  • CVE-2021-24781MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.01

    The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)

  • CVE-2021-24583MedSep 20, 2021
    risk 0.28cvss 4.3epss 0.02

    The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as…

  • CVE-2021-32002MedAug 5, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

  • CVE-2021-34627MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

  • CVE-2021-34626MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

  • CVE-2021-28579MedJun 28, 2021
    risk 0.28cvss 4.3epss 0.01

    Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants.

  • CVE-2020-27831MedMay 27, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

  • CVE-2021-1515MedMay 6, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage Software is running in multi-tenant mode.…

  • CVE-2021-1477MedApr 29, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in…

  • CVE-2021-1467MedApr 8, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the…

  • CVE-2020-8275MedJan 6, 2021
    risk 0.28cvss 4.3epss 0.02

    Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would…

  • CVE-2019-11786MedDec 22, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.

  • CVE-2019-11785MedDec 22, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future…

  • CVE-2020-25701MedNov 19, 2020
    risk 0.28cvss 5.3epss 0.01

    If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to…

  • CVE-2020-26077MedNov 18, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to improper access…