VYPR

CWE-425

Direct Request ('Forced Browsing')

BaseIncomplete

Description

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-143 · CAPEC-144 · CAPEC-668 · CAPEC-87

CVEs mapped to this weakness (238)

page 9 of 12
  • CVE-2017-2143MedApr 28, 2017
    risk 0.35cvss 5.3epss 0.01

    CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.

  • CVE-2017-2139MedApr 28, 2017
    risk 0.35cvss 5.3epss 0.01

    CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.

  • CVE-2005-1688MedMay 20, 2005
    risk 0.35cvss 5.3epss 0.02

    Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.

  • CVE-2004-2257MedDec 31, 2004
    risk 0.35cvss 5.3epss 0.02

    phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

  • CVE-2026-29909MedMar 30, 2026
    risk 0.34cvss 5.3epss 0.00

    MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without…

  • CVE-2026-4900MedMar 26, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to…

  • CVE-2026-4532MedMar 22, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories…

  • CVE-2026-1978MedFeb 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack…

  • CVE-2025-6352MedJun 20, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of the file /vote.php of the component Backend. The manipulation leads to direct request. It is possible to launch the attack remotely. The…

  • CVE-2025-2595MedApr 23, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.

  • CVE-2025-2147MedMar 10, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to…

  • CVE-2024-9945MedDec 13, 2024
    risk 0.34cvss 5.3epss 0.00

    An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.

  • CVE-2024-7153MedJul 27, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic has been found in Netgear WN604 up to 20240719. Affected is an unknown function of the file siteSurvey.php. The manipulation leads to direct request. It is possible to launch the attack remotely. The exploit has been disclosed to the…

  • CVE-2024-6414MedJun 30, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component Export Page. The manipulation of the argument ID leads to direct request. It is possible to launch the…

  • CVE-2024-2730MedApr 10, 2024
    risk 0.34cvss 5.3epss 0.01

    Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the CVE no patch is available

  • CVE-2023-45598MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

  • CVE-2023-45596MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. This issue affects: AiLux imx6 bundle below version…

  • CVE-2023-46186MedFeb 14, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper access controls. IBM X-Force ID: 269929.

  • CVE-2025-67844MedDec 19, 2025
    risk 0.33cvss 5.0epss 0.00

    The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It fails to validate that the repository owner and name fields provided during configuration belong to the…

  • CVE-2025-31971MedAug 28, 2025
    risk 0.33cvss 5.1epss 0.00

    AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.