CWE-425
Direct Request ('Forced Browsing')
Description
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87
CVEs mapped to this weakness (238)
page 6 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-65011 | Hig | 0.46 | — | 0.00 | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or… | ||
| CVE-2026-34028 | Med | 0.45 | — | 0.00 | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as… | ||
| CVE-2026-25679 | Hig | 0.42 | 7.5 | 0.01 | Mar 6, 2026 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | ||
| CVE-2025-26381 | — | Med | 0.42 | — | 0.00 | Dec 17, 2025 | Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information. | |
| CVE-2025-55736 | Med | 0.42 | 6.5 | 0.00 | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file. | ||
| CVE-2025-52920 | Med | 0.42 | 6.4 | 0.00 | Jun 23, 2025 | Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their… | ||
| CVE-2023-50935 | Med | 0.42 | 6.5 | 0.00 | Feb 2, 2024 | IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115. | ||
| CVE-2015-1313 | Med | 0.42 | 6.5 | 0.01 | Jun 29, 2023 | JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request. | ||
| CVE-2023-28160 | Med | 0.42 | 6.5 | 0.01 | Jun 2, 2023 | When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. This vulnerability affects Firefox < 111. | ||
| CVE-2023-1663 | Med | 0.42 | 6.5 | 0.00 | Mar 29, 2023 | Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the… | ||
| CVE-2022-40845 | Med | 0.42 | 6.5 | 0.01 | Nov 15, 2022 | The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information… | ||
| CVE-2022-42197 | Med | 0.42 | 6.5 | 0.01 | Oct 20, 2022 | In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges. | ||
| CVE-2022-1551 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2022 | The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files. | ||
| CVE-2021-40616 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2022 | thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required. | ||
| CVE-2022-24385 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2022 | A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010. | ||
| CVE-2021-24238 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2021 | The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter. | ||
| CVE-2020-13474 | Med | 0.42 | 6.5 | 0.01 | Dec 28, 2020 | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users. | ||
| CVE-2020-8439 | Med | 0.42 | 6.5 | 0.02 | Mar 7, 2020 | Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI. | ||
| CVE-2019-17646 | Hig | 0.42 | 7.5 | 0.02 | Mar 5, 2020 | An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService. | ||
| CVE-2018-19143 | Med | 0.42 | 6.5 | 0.01 | Nov 11, 2018 | Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled. |
- risk 0.46cvss —epss 0.00
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or…
- risk 0.45cvss —epss 0.00
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as…
- risk 0.42cvss 7.5epss 0.01
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
- risk 0.42cvss —epss 0.00
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information.
- risk 0.42cvss 6.5epss 0.00
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
- risk 0.42cvss 6.4epss 0.00
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their…
- risk 0.42cvss 6.5epss 0.00
IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115.
- risk 0.42cvss 6.5epss 0.01
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
- risk 0.42cvss 6.5epss 0.01
When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. This vulnerability affects Firefox < 111.
- risk 0.42cvss 6.5epss 0.00
Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the…
- risk 0.42cvss 6.5epss 0.01
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information…
- risk 0.42cvss 6.5epss 0.01
In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.
- risk 0.42cvss 6.5epss 0.01
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
- risk 0.42cvss 6.5epss 0.01
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.
- risk 0.42cvss 6.5epss 0.01
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
- risk 0.42cvss 6.5epss 0.01
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter.
- risk 0.42cvss 6.5epss 0.01
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
- risk 0.42cvss 6.5epss 0.02
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI.
- risk 0.42cvss 7.5epss 0.02
An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.
- risk 0.42cvss 6.5epss 0.01
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.