VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 38 of 82
  • CVE-2025-0849MedJan 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack…

  • CVE-2024-8676HigNov 26, 2024
    risk 0.41cvss 7.4epss 0.01

    A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the…

  • CVE-2020-3539MedNov 18, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. The vulnerability is due to a failure to limit access to resources that…

  • CVE-2024-9297MedSep 28, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument page with the input trains/schedules/system_info…

  • CVE-2024-9082MedSep 22, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save of the component User Creation Handler. The manipulation of the argument Type with the…

  • CVE-2024-7851MedAug 16, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save of the component Add User Handler. The manipulation leads to improper authorization. The…

  • CVE-2021-4335MedOct 20, 2023
    risk 0.41cvss 6.3epss 0.00

    The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated…

  • CVE-2023-2345MedApr 27, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The manipulation leads to improper authorization. The attack may…

  • CVE-2020-14486MedJul 29, 2020
    risk 0.41cvss 6.3epss 0.01

    An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.

  • CVE-2016-9575MedMar 13, 2018
    risk 0.41cvss 6.3epss 0.01

    Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates…

  • CVE-2026-60842MedJul 21, 2026
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-11462HigJun 7, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in…

  • CVE-2026-7505HigApr 30, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used.…

  • CVE-2026-35476HigApr 8, 2026
    risk 0.40cvss 7.2epss 0.00

    InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly…

  • CVE-2026-28448HigMar 5, 2026
    risk 0.40cvss 7.3epss 0.00

    OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twitch users to trigger agent dispatch.…

  • CVE-2025-53056MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2025-61524HigOct 8, 2025
    risk 0.40cvss 7.2epss 0.01

    An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification…

  • CVE-2025-50073MedJul 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2024-57954MedFeb 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-51525MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.