VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 30 of 41
  • CVE-2024-25584MedSep 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails.…

  • CVE-2024-2382MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates a orders payment status. This makes it…

  • CVE-2024-1718MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for…

  • CVE-2024-31341MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.

  • CVE-2023-35764MedApr 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.

  • CVE-2024-1321MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for…

  • CVE-2023-42782MedOct 10, 2023
    risk 0.34cvss 5.3epss 0.00

    A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.

  • CVE-2023-35906MedSep 5, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.

  • CVE-2023-30559MedJul 13, 2023
    risk 0.34cvss 5.2epss 0.00

    The firmware update package for the wireless card is not properly signed and can be modified.

  • CVE-2020-1755MedAug 16, 2022
    risk 0.34cvss 5.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

  • CVE-2020-8660MedMar 4, 2020
    risk 0.34cvss 5.3epss 0.01

    CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain,…

  • CVE-2019-11737MedSep 27, 2019
    risk 0.34cvss 5.3epss 0.01

    If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability affects Firefox < 69.

  • CVE-2018-17938MedOct 3, 2018
    risk 0.34cvss 5.3epss 0.01

    Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.

  • CVE-2017-10862MedOct 12, 2017
    risk 0.34cvss 5.3epss 0.01

    jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.

  • CVE-2026-68945MedAug 3, 2026
    risk 0.33cvss 6.1epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient…

  • CVE-2026-54266MedJun 22, 2026
    risk 0.33cvss 6.1epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be…

  • CVE-2026-1195MedJan 20, 2026
    risk 0.33cvss 5.0epss 0.00

    A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The…

  • CVE-2022-33861MedNov 25, 2024
    risk 0.33cvss 5.1epss 0.00

    IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.

  • CVE-2023-45586MedMay 14, 2024
    risk 0.33cvss 5.0epss 0.00

    An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7…

  • CVE-2023-44402MedDec 1, 2023
    risk 0.33cvss 6.1epss 0.00

    Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` fuses enabled. Apps without these fuses enabled are not…