VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 52 of 82
  • CVE-2024-11768MedDec 19, 2024
    risk 0.34cvss 5.3epss 0.00

    The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers…

  • CVE-2024-12347MedDec 9, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Monitoring Interface. The manipulation…

  • CVE-2024-11306MedNov 18, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization. The attack may be…

  • CVE-2024-38370MedNov 15, 2024
    risk 0.34cvss 5.3epss 0.00

    GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.

  • CVE-2024-10598MedOct 31, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to improper authorization. The…

  • CVE-2020-36841MedOct 16, 2024
    risk 0.34cvss 5.3epss 0.00

    The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send…

  • CVE-2024-7799MedAug 15, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/bidding/admin/users.php. The manipulation leads to improper authorization.…

  • CVE-2024-6384MedAug 13, 2024
    risk 0.34cvss 5.3epss 0.00

    "Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise…

  • CVE-2024-43045MedAug 7, 2024
    risk 0.34cvss 6.3epss 0.04

    Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".

  • CVE-2024-37154MedJun 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 18.1.0 and earlier.

  • CVE-2024-23806MedFeb 7, 2024
    risk 0.34cvss 5.3epss 0.00

    Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

  • CVE-2023-6496MedJan 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.

  • CVE-2023-28318MedMay 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.

  • CVE-2023-28317MedMay 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.

  • CVE-2023-1167MedApr 5, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.

  • CVE-2022-3187MedDec 21, 2022
    risk 0.34cvss 5.3epss 0.00

    Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of…

  • CVE-2022-42961MedOct 15, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatures. These signatures can…

  • CVE-2022-39862MedOct 7, 2022
    risk 0.34cvss 5.3epss 0.01

    Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.

  • CVE-2022-33712MedJul 12, 2022
    risk 0.34cvss 5.3epss 0.01

    Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.

  • CVE-2021-42000MedFeb 10, 2022
    risk 0.34cvss 5.3epss 0.01

    When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.