VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 297 of 406
  • CVE-2024-1472MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's maintenance mode obtain post and page content via REST API.

  • CVE-2024-1044MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to…

  • CVE-2024-1476MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.00

    The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages…

  • CVE-2024-0975MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.01

    The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when…

  • CVE-2022-45320MedFeb 20, 2024
    risk 0.34cvss 6.3epss 0.00

    Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.

  • CVE-2024-23447MedFeb 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications…

  • CVE-2023-41603MedJan 10, 2024
    risk 0.34cvss 5.3epss 0.00

    D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.

  • CVE-2022-41677MedDec 18, 2023
    risk 0.34cvss 5.3epss 0.01

    An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the…

  • CVE-2023-41570MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.00

    MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

  • CVE-2023-46755MedNov 8, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.

  • CVE-2023-46666MedOct 26, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all…

  • CVE-2023-41721MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with…

  • CVE-2023-39731MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.00

    The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-41311MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.

  • CVE-2023-3700MedJul 17, 2023
    risk 0.34cvss 6.3epss 0.00

    Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

  • CVE-2023-3096MedJun 5, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been declared as critical. This vulnerability affects the function changedSource. The manipulation leads to improper access controls. An attack has to be approached locally. The exploit has been…

  • CVE-2022-32582MedMay 10, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2023-29921MedApr 19, 2023
    risk 0.34cvss 5.3epss 0.01

    PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.

  • CVE-2023-29140MedMar 31, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.

  • CVE-2023-27268MedMar 14, 2023
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to…