VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (244)

page 10 of 13
  • CVE-2023-45598MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

  • CVE-2023-45596MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. This issue affects: AiLux imx6 bundle below version…

  • CVE-2023-46186MedFeb 14, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper access controls. IBM X-Force ID: 269929.

  • CVE-2025-67844MedDec 19, 2025
    risk 0.33cvss 5.0epss 0.00

    The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It fails to validate that the repository owner and name fields provided during configuration belong to the…

  • CVE-2025-31971MedAug 28, 2025
    risk 0.33cvss 5.1epss 0.00

    AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.

  • CVE-2025-46690MedApr 27, 2025
    risk 0.33cvss 5.0epss 0.00

    Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.

  • CVE-2023-5702MedOct 23, 2023
    risk 0.32cvss 4.3epss 0.15

    A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used.…

  • CVE-2026-21760MedJul 17, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.

  • CVE-2025-47226MedMay 2, 2025
    risk 0.29cvss 5.0epss 0.01

    Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

  • CVE-2026-14953MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

  • CVE-2026-7500MedApr 30, 2026
    risk 0.28cvss 5.4epss 0.00

    When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the…

  • CVE-2024-58343MedApr 16, 2026
    risk 0.28cvss 4.3epss 0.00

    Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.

  • CVE-2026-34051MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct…

  • CVE-2025-6195MedNov 26, 2025
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

  • CVE-2025-41404MedJun 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.

  • CVE-2025-27581MedApr 24, 2025
    risk 0.28cvss 4.3epss 0.00

    NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

  • CVE-2024-55075MedJan 6, 2025
    risk 0.28cvss 4.3epss 0.01

    Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.

  • CVE-2024-0861MedFeb 22, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary…

  • CVE-2024-0456MedJan 26, 2024
    risk 0.28cvss 4.3epss 0.00

    An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

  • CVE-2023-44320MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router…