VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (729)

page 17 of 37
  • CVE-2024-8183HigMar 20, 2025
    risk 0.42cvss 7.6epss 0.00

    A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality,…

  • CVE-2025-25302MedMar 3, 2025
    risk 0.42cvss 6.5epss 0.00

    Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be…

  • CVE-2025-24010MedJan 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in…

  • CVE-2025-23109MedJan 11, 2025
    risk 0.42cvss 6.5epss 0.00

    Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.

  • CVE-2024-44187MedSep 17, 2024
    risk 0.42cvss 6.5epss 0.01

    A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.

  • CVE-2024-36472MedMay 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead…

  • CVE-2024-2447MedApr 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.

  • CVE-2024-2182MedMar 12, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a…

  • CVE-2024-0814MedJan 24, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-37210MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.00

    A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.

  • CVE-2023-28164MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

  • CVE-2023-23601MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

  • CVE-2023-29868MedMay 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

  • CVE-2023-29867MedMay 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.

  • CVE-2023-0132MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-38472MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects…

  • CVE-2022-22757MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. *This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*.…

  • CVE-2022-42975HigOct 17, 2022
    risk 0.42cvss 7.5epss 0.01

    socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.

  • CVE-2022-41294MedOct 6, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.

  • CVE-2022-1497MedJul 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.