VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 80 of 82
  • CVE-2024-36399HigJun 6, 2024
    risk 0.00cvss 8.2epss 0.00

    Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is…

  • CVE-2024-27930MedMar 18, 2024
    risk 0.00cvss 6.5epss 0.01

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version…

  • CVE-2023-52139CriDec 29, 2023
    risk 0.00cvss 9.0epss 0.01

    Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/b…

  • CVE-2023-5948MedNov 3, 2023
    risk 0.00cvss 5.5epss 0.00

    Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

  • CVE-2023-33183LowMay 30, 2023
    risk 0.00cvss 2.6epss 0.00

    Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3

  • CVE-2023-2950HigMay 28, 2023
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.

  • CVE-2023-28623MedMay 19, 2023
    risk 0.00cvss 6.5epss 0.01

    Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in…

  • CVE-2022-4879MedJan 6, 2023
    risk 0.00cvss 4.6epss 0.01

    A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to…

  • CVE-2022-23542HigDec 20, 2022
    risk 0.00cvss 7.7epss 0.01

    OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in…

  • CVE-2022-39356HigNov 2, 2022
    risk 0.00cvss 8.9epss 0.01

    Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest…

  • CVE-2022-39329LowOct 27, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without…

  • CVE-2022-2901HigSep 6, 2022
    risk 0.00cvss 7.1epss 0.01

    Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

  • CVE-2022-2595CriAug 1, 2022
    risk 0.00cvss 10.0epss 0.01

    Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.

  • CVE-2022-31168MedJul 22, 2022
    risk 0.00cvss 5.4epss 0.01

    Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server…

  • CVE-2022-31025LowJun 7, 2022
    risk 0.00cvss 2.6epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_users` check and invites by staff…

  • CVE-2022-29236MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a…

  • CVE-2022-29234MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a…

  • CVE-2022-29233MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of…

  • CVE-2022-1224MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-0406MedApr 3, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.