VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 266 of 327
  • CVE-2024-13430MedMar 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be…

  • CVE-2024-13635MedMar 7, 2025
    risk 0.21cvss 4.3epss 0.00

    The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data…

  • CVE-2024-13855MedFeb 20, 2025
    risk 0.21cvss 4.3epss 0.00

    The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This makes it possible for authenticated…

  • CVE-2024-13229MedFeb 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated…

  • CVE-2025-21337LowFeb 11, 2025
    risk 0.21cvss 3.3epss 0.01

    Windows NTFS Elevation of Privilege Vulnerability

  • CVE-2025-1115LowFeb 8, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_device_control/sys_device_find/sys_device_init/sys_device_open/sys_device_read/sys_device_register/sys_device_write/sys_event_delete/s…

  • CVE-2024-13514MedFeb 4, 2025
    risk 0.21cvss 4.3epss 0.00

    The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via the 'bsb-slider' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for…

  • CVE-2024-9503MedDec 20, 2024
    risk 0.21cvss 4.3epss 0.00

    The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option',…

  • CVE-2024-48899MedNov 20, 2024
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

  • CVE-2021-3987MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary…

  • CVE-2024-7429MedNov 5, 2024
    risk 0.21cvss 4.3epss 0.00

    The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with…

  • CVE-2024-10241MedOct 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

  • CVE-2024-42988MedOct 9, 2024
    risk 0.21cvss 4.3epss 0.00

    Lack of access control in ChallengeSolves (/api/v1/challenges//solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+.

  • CVE-2024-28170LowSep 16, 2024
    risk 0.21cvss 3.3epss 0.00

    Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2024-3127MedAug 22, 2024
    risk 0.21cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups…

  • CVE-2024-43397MedAug 20, 2024
    risk 0.21cvss 4.3epss 0.00

    Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue…

  • CVE-2024-39839MedAug 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would…

  • CVE-2023-42957LowJul 29, 2024
    risk 0.21cvss 3.3epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.

  • CVE-2024-37147MedJul 10, 2024
    risk 0.21cvss 4.3epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.

  • CVE-2023-6491MedJun 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with…