VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (238)

page 4 of 12
  • CVE-2018-16706HigSep 14, 2018
    risk 0.51cvss 7.5epss 0.22

    LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

  • CVE-2026-34056HigMar 26, 2026
    risk 0.50cvss 7.7epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper…

  • CVE-2021-42671HigNov 5, 2021
    risk 0.50cvss 7.5epss 0.20

    An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server…

  • CVE-2026-0790HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.01

    ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required to exploit this…

  • CVE-2025-48207HigMay 21, 2025
    risk 0.49cvss 8.6epss 0.00

    The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.

  • CVE-2025-48201HigMay 21, 2025
    risk 0.49cvss 8.6epss 0.00

    The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.

  • CVE-2024-39868HigJul 9, 2024
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit VxLAN…

  • CVE-2024-39867HigJul 9, 2024
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit device…

  • CVE-2022-42438HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210.

  • CVE-2022-47700HigJan 31, 2023
    risk 0.49cvss 7.5epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid session or authentication.

  • CVE-2022-2544HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.03

    The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

  • CVE-2022-34570HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.

  • CVE-2022-2192HigJul 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior…

  • CVE-2022-31847HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.06

    A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

  • CVE-2022-31484HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to…

  • CVE-2022-31480HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain…

  • CVE-2022-28991HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

  • CVE-2022-27480HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.

  • CVE-2021-24831HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

  • CVE-2021-24695HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.02

    The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and…