VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 314 of 327
  • CVE-2018-25093MedNov 6, 2023
    risk 0.00cvss 5.5epss 0.00

    A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to…

  • CVE-2018-25092MedNov 5, 2023
    risk 0.00cvss 5.5epss 0.00

    A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version…

  • CVE-2023-5833HigOct 30, 2023
    risk 0.00cvss 8.8epss 0.01

    Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

  • CVE-2023-5353MedOct 3, 2023
    risk 0.00cvss 6.5epss 0.01

    Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2023-4650MedAug 31, 2023
    risk 0.00cvss 4.7epss 0.00

    Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-39963HigAug 10, 2023
    risk 0.00cvss 8.1epss 0.00

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password confirmation allowed an attacker, after…

  • CVE-2023-39962HigAug 10, 2023
    risk 0.00cvss 7.7epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malicious user could delete any personal or…

  • CVE-2023-39961LowAug 10, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could add the image inline…

  • CVE-2023-39959LowAug 10, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.9, 26.0.4, and 27.0.1, unauthenticated users could send a DAV request which reveals whether a calendar or an address book with the given…

  • CVE-2023-39952MedAug 10, 2023
    risk 0.00cvss 6.5epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files inside a subfolder of a groupfolder accessible to them,…

  • CVE-2023-35927HigJun 23, 2023
    risk 0.00cvss 7.6epss 0.01

    NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until…

  • CVE-2023-35173MedJun 23, 2023
    risk 0.00cvss 5.7epss 0.00

    Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end…

  • CVE-2023-2946HigMay 27, 2023
    risk 0.00cvss 8.1epss 0.00

    Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2023-2944MedMay 27, 2023
    risk 0.00cvss 5.4epss 0.00

    Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2023-2845HigMay 23, 2023
    risk 0.00cvss 8.1epss 0.01

    Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

  • CVE-2023-2674MedMay 12, 2023
    risk 0.00cvss 4.3epss 0.01

    Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2023-30539MedApr 17, 2023
    risk 0.00cvss 6.5epss 0.01

    Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that…

  • CVE-2023-28845LowMar 31, 2023
    risk 0.00cvss 3.5epss 0.00

    Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation,…

  • CVE-2023-28844MedMar 31, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users…

  • CVE-2023-28645MedMar 31, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the…