VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 309 of 406
  • CVE-2024-13138MedJan 5, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The manipulation of the argument test leads to unrestricted…

  • CVE-2024-11214MedNov 14, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be…

  • CVE-2024-11211MedNov 14, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the…

  • CVE-2024-11000MedNov 8, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted…

  • CVE-2024-10999MedNov 8, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible…

  • CVE-2024-43456MedOct 8, 2024
    risk 0.31cvss 4.8epss 0.01

    Windows Remote Desktop Services Tampering Vulnerability

  • CVE-2024-42794MedSep 16, 2024
    risk 0.31cvss 4.7epss 0.00

    Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.

  • CVE-2024-8071MedAug 22, 2024
    risk 0.31cvss 4.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to…

  • CVE-2024-41732MedAug 13, 2024
    risk 0.31cvss 4.7epss 0.00

    SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could …

  • CVE-2024-21145MedJul 16, 2024
    risk 0.31cvss 4.8epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK:…

  • CVE-2024-35222MedMay 23, 2024
    risk 0.31cvss 5.9epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the `dangerousRemoteDomainIpcAccess` in v1 and in the `capabilities` in v2. Valid…

  • CVE-2023-43487MedMay 16, 2024
    risk 0.31cvss 4.7epss 0.00

    Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-31207MedApr 4, 2024
    risk 0.31cvss 5.9epss 0.01

    Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13,…

  • CVE-2024-1343MedFeb 19, 2024
    risk 0.31cvss 4.7epss 0.00

    A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'.

  • CVE-2022-48615MedDec 12, 2023
    risk 0.31cvss 4.8epss 0.00

    An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.

  • CVE-2023-2979MedMay 30, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2022-41769MedMay 10, 2023
    risk 0.31cvss 4.8epss 0.00

    Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-21490MedMay 4, 2023
    risk 0.31cvss 4.7epss 0.00

    Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.

  • CVE-2022-20728MedSep 30, 2022
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the…

  • CVE-2021-1113MedAug 11, 2021
    risk 0.31cvss 4.7epss 0.00

    NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauthorized modification to camera resources, which may result in complete denial of service and partial loss of data integrity for all clients.