VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (238)

page 2 of 12
  • CVE-2018-18922CriDec 13, 2018
    risk 0.64cvss 9.8epss 0.02

    add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.

  • CVE-2018-6624CriFeb 5, 2018
    risk 0.64cvss 9.8epss 0.02

    OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screen, as demonstrated by monitor.html.

  • CVE-2021-26085MedKEVAug 3, 2021
    risk 0.63cvss 5.3epss 1.00

    Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

  • CVE-2019-12583CriJun 27, 2019
    risk 0.63cvss 9.1epss 0.44

    Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

  • CVE-2002-1798CriDec 31, 2002
    risk 0.63cvss 9.1epss 0.05

    MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.

  • CVE-2024-45195HigKEVSep 4, 2024
    risk 0.62cvss 7.5epss 1.00

    Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

  • CVE-2025-52024CriJan 23, 2026
    risk 0.61cvss 9.4epss 0.00

    A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs, an attacker is presented with a directory-style index listing all available backend services and…

  • CVE-2019-14347HigAug 6, 2019
    risk 0.61cvss 8.8epss 0.09

    Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.

  • CVE-2025-1542CriMar 26, 2025
    risk 0.60cvss epss 0.00

    Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before…

  • CVE-2026-22732CriMar 19, 2026
    risk 0.59cvss 9.1epss 0.00

    When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from…

  • CVE-2024-33897CriAug 6, 2024
    risk 0.59cvss 9.1epss 0.01

    A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

  • CVE-2022-41746CriOct 10, 2022
    risk 0.59cvss 9.1epss 0.01

    A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex…

  • CVE-2017-10833CriAug 29, 2017
    risk 0.59cvss 9.1epss 0.02

    "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors.

  • CVE-2022-28799HigJun 2, 2022
    risk 0.58cvss 8.8epss 0.16

    The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover…

  • CVE-2018-3774CriAug 12, 2018
    risk 0.58cvss 10.0epss 0.04

    Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.

  • CVE-2022-42238HigOct 11, 2022
    risk 0.57cvss 8.8epss 0.01

    A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.

  • CVE-2021-44582HigJun 10, 2022
    risk 0.57cvss 8.8epss 0.01

    A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.

  • CVE-2020-24660CriSep 14, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

  • CVE-2020-11561HigApr 7, 2020
    risk 0.57cvss 8.8epss 0.02

    In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.

  • CVE-2019-11326HigSep 20, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product is protected by a login. A guest is allowed to login. Once logged in as a guest, an attacker can browse a URL to read the password of the…