VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 346 of 404
  • CVE-2024-7429MedNov 5, 2024
    risk 0.21cvss 4.3epss 0.00

    The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with…

  • CVE-2024-10241MedOct 29, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

  • CVE-2024-42988MedOct 9, 2024
    risk 0.21cvss 4.3epss 0.00

    Lack of access control in ChallengeSolves (/api/v1/challenges//solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+.

  • CVE-2024-28170LowSep 16, 2024
    risk 0.21cvss 3.3epss 0.00

    Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2024-3127MedAug 22, 2024
    risk 0.21cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups…

  • CVE-2024-43397MedAug 20, 2024
    risk 0.21cvss 4.3epss 0.00

    Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue…

  • CVE-2024-39839MedAug 1, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would…

  • CVE-2023-42957LowJul 29, 2024
    risk 0.21cvss 3.3epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.

  • CVE-2024-37147MedJul 10, 2024
    risk 0.21cvss 4.3epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.

  • CVE-2023-6491MedJun 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with…

  • CVE-2024-1376MedMay 24, 2024
    risk 0.21cvss 4.3epss 0.00

    The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with subscriber access or…

  • CVE-2024-1230MedMay 14, 2024
    risk 0.21cvss 4.3epss 0.01

    The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to…

  • CVE-2023-6810MedMay 7, 2024
    risk 0.21cvss 4.3epss 0.00

    The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with author…

  • CVE-2024-23238LowMar 8, 2024
    risk 0.21cvss 3.3epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.

  • CVE-2024-0766MedFeb 28, 2024
    risk 0.21cvss 4.3epss 0.00

    The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up to, and including, 1.4.4. This makes it possible for…

  • CVE-2024-1053MedFeb 22, 2024
    risk 0.21cvss 4.3epss 0.00

    The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level…

  • CVE-2024-25981MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

  • CVE-2024-25980MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

  • CVE-2024-25120MedFeb 13, 2024
    risk 0.21cvss 4.3epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a…

  • CVE-2024-24751MedFeb 13, 2024
    risk 0.21cvss 4.3epss 0.00

    sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the…