VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 277 of 406
  • CVE-2022-32255MedJun 14, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to limited information.

  • CVE-2022-1659MedJun 13, 2022
    risk 0.35cvss 5.4epss 0.01

    Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter.…

  • CVE-2022-1658MedJun 13, 2022
    risk 0.35cvss 5.4epss 0.01

    Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using…

  • CVE-2022-1656MedJun 13, 2022
    risk 0.35cvss 5.4epss 0.01

    Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin…

  • CVE-2022-1753MedMay 17, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack…

  • CVE-2022-0574MedMay 16, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

  • CVE-2019-25060MedMay 9, 2022
    risk 0.35cvss 5.3epss 0.02

    The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

  • CVE-2020-14504MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.01

    The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.

  • CVE-2022-0731MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2020-13676MedFeb 11, 2022
    risk 0.35cvss 6.5epss 0.01

    The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

  • CVE-2022-0273MedJan 30, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in Pypi calibreweb prior to 0.6.16.

  • CVE-2022-21305MedJan 19, 2022
    risk 0.35cvss 5.3epss 0.03

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable…

  • CVE-2022-21291MedJan 19, 2022
    risk 0.35cvss 5.3epss 0.03

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable…

  • CVE-2021-4194MedJan 6, 2022
    risk 0.35cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2021-3992MedDec 1, 2021
    risk 0.35cvss 6.5epss 0.01

    kimai2 is vulnerable to Improper Access Control

  • CVE-2021-34794MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data.…

  • CVE-2021-24635MedSep 20, 2021
    risk 0.35cvss 5.4epss 0.01

    The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and…

  • CVE-2021-40347MedSep 10, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

  • CVE-2021-25448MedAug 5, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.

  • CVE-2021-25447MedAug 5, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.