VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 9 of 32
  • CVE-2023-37057CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentication mechanism.

  • CVE-2024-4552CriJun 4, 2024
    risk 0.64cvss 9.8epss 0.01

    The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.6.0. This is due to insufficient verification on the user being supplied during the social login through the plugin. This makes it possible for…

  • CVE-2024-4544CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.7. This is due to insufficient verification on the user being supplied during a social login through the plugin. This makes it…

  • CVE-2024-4393CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for…

  • CVE-2024-2055CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

  • CVE-2023-2437CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.07

    The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers…

  • CVE-2023-3277CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.03

    The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as…

  • CVE-2023-41351CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log…

  • CVE-2023-4702CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

  • CVE-2023-32002CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.02

    The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note…

  • CVE-2023-3249CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated…

  • CVE-2020-36713CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new…

  • CVE-2023-2734CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.04

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible…

  • CVE-2023-2733CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for…

  • CVE-2023-2704CriMay 19, 2023
    risk 0.64cvss 9.8epss 0.02

    The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated…

  • CVE-2023-2499CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for…

  • CVE-2023-2027CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.01

    The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for…

  • CVE-2023-22495CriJan 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token…

  • CVE-2022-27510CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauthorized access to Gateway user capabilities

  • CVE-2022-34372CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter…