VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 296 of 406
  • CVE-2024-2191MedJun 27, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

  • CVE-2024-38873MedJun 21, 2024
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only…

  • CVE-2024-5687MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the…

  • CVE-2024-0972MedJun 6, 2024
    risk 0.34cvss 5.3epss 0.00

    The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All Other Sections On Your Site Will be…

  • CVE-2024-0434MedMay 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to, and including, 1.7.1. This makes it…

  • CVE-2023-43847MedMay 28, 2024
    risk 0.34cvss 5.3epss 0.01

    Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to control all the outlets as if they were the administrator via HTTP POST requests.

  • CVE-2024-1678MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's private site feature and view…

  • CVE-2024-1584MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1.…

  • CVE-2024-22830MedMay 1, 2024
    risk 0.34cvss 5.3epss 0.00

    Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate privileges from regular user to System or PPL level.

  • CVE-2024-28978MedMay 1, 2024
    risk 0.34cvss 5.2epss 0.00

    Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to unauthorized access to resources.

  • CVE-2024-0899MedApr 9, 2024
    risk 0.34cvss 5.3epss 0.01

    The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for…

  • CVE-2024-1418MedApr 4, 2024
    risk 0.34cvss 5.3epss 0.00

    The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST API even when maintenance mode is…

  • CVE-2024-1462MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.01

    The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode.

  • CVE-2024-1370MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers,…

  • CVE-2024-0687MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.01

    The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages via…

  • CVE-2023-6785MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.01

    The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately…

  • CVE-2024-1478MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.01

    The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content…

  • CVE-2024-1088MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.01

    The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including post titles and…

  • CVE-2024-1492MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthenticated attackers to obtain shipping…

  • CVE-2024-1475MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content thus bypassing the protection…