VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (238)

page 1 of 12
  • CVE-2024-0204CriJan 22, 2024
    risk 0.74cvss 9.8epss 0.95

    Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

  • CVE-2018-19207CriNov 12, 2018
    risk 0.74cvss 9.8epss 0.88

    The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.

  • CVE-2017-17736CriMar 23, 2018
    risk 0.69cvss 9.8epss 0.69

    Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

  • CVE-2020-35391CriJan 1, 2021
    risk 0.68cvss 9.6epss 0.35

    Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either…

  • CVE-2017-14244CriSep 17, 2017
    risk 0.68cvss 9.8epss 0.17

    An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

  • CVE-2019-16340CriNov 21, 2019
    risk 0.65cvss 9.8epss 0.19

    Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.

  • CVE-2022-43110CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface…

  • CVE-2025-26689CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.

  • CVE-2024-24592CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.

  • CVE-2022-45276CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.

  • CVE-2022-26279CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

  • CVE-2021-36560CriNov 2, 2021
    risk 0.64cvss 9.8epss 0.01

    Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.

  • CVE-2021-36745CriSep 29, 2021
    risk 0.64cvss 9.8epss 0.09

    A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected…

  • CVE-2021-24215CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.10

    An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a…

  • CVE-2019-12768CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.

  • CVE-2020-24203CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.04

    Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

  • CVE-2019-9584CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.03

    eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/…

  • CVE-2019-9884CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.03

    eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.

  • CVE-2019-9552CriMar 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.

  • CVE-2019-7736CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.