VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 30 of 82
  • CVE-2024-11860MedNov 27, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant of the component POST Request Handler. The manipulation of the argument id leads to…

  • CVE-2022-31669MedNov 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag…

  • CVE-2022-31667MedNov 14, 2024
    risk 0.42cvss 6.4epss 0.01

    Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name…

  • CVE-2024-45132MedOct 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect…

  • CVE-2024-20414MedSep 25, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly…

  • CVE-2024-46942MedSep 15, 2024
    risk 0.42cvss 6.5epss 0.00

    In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.

  • CVE-2024-43482MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Microsoft Outlook for iOS Information Disclosure Vulnerability

  • CVE-2024-38231MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.02

    Windows Remote Desktop Licensing Service Denial of Service Vulnerability

  • CVE-2024-42490HigAug 22, 2024
    risk 0.42cvss 7.5epss 0.00

    authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs//view_certificate/,…

  • CVE-2024-6347MedAug 15, 2024
    risk 0.42cvss 6.5epss 0.00

    * Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU's programming session. * No preconditions implemented for…

  • CVE-2024-41670HigJul 26, 2024
    risk 0.42cvss 7.5epss 0.00

    In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment…

  • CVE-2024-3027MedApr 13, 2024
    risk 0.42cvss 6.4epss 0.00

    The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access…

  • CVE-2024-1289MedApr 9, 2024
    risk 0.42cvss 6.5epss 0.00

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.3 due to missing validation on a user controlled key when looking up order information. This makes it possible for…

  • CVE-2024-26193MedApr 9, 2024
    risk 0.42cvss 6.4epss 0.01

    Azure Migrate Remote Code Execution Vulnerability

  • CVE-2024-29033HigMar 20, 2024
    risk 0.42cvss 7.5epss 0.01

    OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. `GoogleOAuthenticator.hosted_domain` is used to restrict what Google accounts can be authorized access to a…

  • CVE-2024-23649HigJan 24, 2024
    risk 0.42cvss 7.5epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even when they're neither sender nor recipient of the message. The API response to creating a private message report contains the…

  • CVE-2023-46942HigJan 13, 2024
    risk 0.42cvss 7.5epss 0.01

    Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

  • CVE-2023-32678MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete…

  • CVE-2023-38508MedAug 24, 2023
    risk 0.42cvss 6.5epss 0.01

    Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, the preview of an artifact link with a type does not…

  • CVE-2023-36611MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.01

    The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.