VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (238)

page 12 of 12
  • CVE-2025-57823LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor…

  • CVE-2023-22834LowJun 27, 2023
    risk 0.18cvss 2.7epss 0.00

    The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.

  • CVE-2026-9610LowJun 22, 2026
    risk 0.15cvss 2.3epss 0.00

    IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.

  • CVE-2023-45809LowOct 19, 2023
    risk 0.11cvss 2.7epss 0.00

    Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for the Wagtail admin can make a direct URL request to the admin view that handles bulk actions on user accounts. While authentication rules prevent the user from…

  • CVE-2005-1827May 26, 2005
    risk 0.05cvss epss 0.20

    D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.

  • CVE-2005-1654May 18, 2005
    risk 0.03cvss epss 0.02

    Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.

  • CVE-2026-60011MedAug 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

  • CVE-2024-23573LowJul 17, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be…

  • CVE-2026-13533MedJun 29, 2026
    risk 0.00cvss 5.3epss 0.00

    A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to…

  • CVE-2025-62778MedOct 27, 2025
    risk 0.00cvss 5.3epss 0.00

    Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.

  • CVE-2019-17645HigMar 5, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.

  • CVE-2015-2873Aug 23, 2015
    risk 0.00cvss epss 0.03

    Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the…

  • CVE-2005-1892Jun 9, 2005
    risk 0.00cvss epss 0.02

    FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.

  • CVE-2005-1698May 24, 2005
    risk 0.00cvss epss 0.01

    PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the…

  • CVE-2005-1697May 24, 2005
    risk 0.00cvss epss 0.01

    The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.

  • CVE-2005-1685May 20, 2005
    risk 0.00cvss epss 0.02

    episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.

  • CVE-2005-1668May 18, 2005
    risk 0.00cvss epss 0.02

    YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.

  • CVE-2004-2144Dec 31, 2004
    risk 0.00cvss epss 0.03

    Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.