VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (785)

page 19 of 40
  • CVE-2023-29868MedMay 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.

  • CVE-2023-29867MedMay 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.

  • CVE-2023-0132MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-38472MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects…

  • CVE-2022-22757MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. *This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*.…

  • CVE-2022-42975HigOct 17, 2022
    risk 0.42cvss 7.5epss 0.01

    socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.

  • CVE-2022-41294MedOct 6, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.

  • CVE-2022-1497MedJul 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.

  • CVE-2022-22594MedMar 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

  • CVE-2022-0120MedFeb 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.

  • CVE-2022-0113MedFeb 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-0111MedFeb 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.

  • CVE-2022-0108MedFeb 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-21712HigFeb 7, 2022
    risk 0.42cvss 7.5epss 0.01

    twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent`…

  • CVE-2020-9060MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of…

  • CVE-2021-4024MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is…

  • CVE-2021-38507MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.01

    The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port…

  • CVE-2021-38497MedNov 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.

  • CVE-2021-21229MedApr 30, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-21211MedApr 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.