VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (238)

page 6 of 12
  • CVE-2025-65011HigDec 18, 2025
    risk 0.46cvss epss 0.00

    In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or…

  • CVE-2026-34028MedJun 15, 2026
    risk 0.45cvss epss 0.00

    The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as…

  • CVE-2026-25679HigMar 6, 2026
    risk 0.42cvss 7.5epss 0.01

    url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

  • CVE-2025-26381MedDec 17, 2025
    risk 0.42cvss epss 0.00

    Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information.

  • CVE-2025-55736MedAug 19, 2025
    risk 0.42cvss 6.5epss 0.00

    flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.

  • CVE-2025-52920MedJun 23, 2025
    risk 0.42cvss 6.4epss 0.00

    Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their…

  • CVE-2023-50935MedFeb 2, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115.

  • CVE-2015-1313MedJun 29, 2023
    risk 0.42cvss 6.5epss 0.01

    JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.

  • CVE-2023-28160MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. This vulnerability affects Firefox < 111.

  • CVE-2023-1663MedMar 29, 2023
    risk 0.42cvss 6.5epss 0.00

    Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the…

  • CVE-2022-40845MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information…

  • CVE-2022-42197MedOct 20, 2022
    risk 0.42cvss 6.5epss 0.01

    In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

  • CVE-2022-1551MedJul 25, 2022
    risk 0.42cvss 6.5epss 0.01

    The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.

  • CVE-2021-40616MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.01

    thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.

  • CVE-2022-24385MedMar 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

  • CVE-2021-24238MedApr 22, 2021
    risk 0.42cvss 6.5epss 0.01

    The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter.

  • CVE-2020-13474MedDec 28, 2020
    risk 0.42cvss 6.5epss 0.01

    In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.

  • CVE-2020-8439MedMar 7, 2020
    risk 0.42cvss 6.5epss 0.02

    Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI.

  • CVE-2019-17646HigMar 5, 2020
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.

  • CVE-2018-19143MedNov 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.