VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 27 of 40
  • CVE-2022-25336MedFeb 18, 2022
    risk 0.35cvss 5.3epss 0.01

    Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.

  • CVE-2021-24775MedFeb 1, 2022
    risk 0.35cvss 5.3epss 0.01

    The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.

  • CVE-2021-42749MedJan 10, 2022
    risk 0.35cvss 5.3epss 0.01

    In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt field is not set.

  • CVE-2021-4194MedJan 6, 2022
    risk 0.35cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2021-39915MedDec 13, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on…

  • CVE-2021-29115MedDec 7, 2021
    risk 0.35cvss 5.3epss 0.02

    An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

  • CVE-2021-43560MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

  • CVE-2021-41532MedNov 19, 2021
    risk 0.35cvss 5.3epss 0.02

    In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

  • CVE-2021-22047MedOct 28, 2021
    risk 0.35cvss 5.3epss 0.01

    In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be…

  • CVE-2021-40497MedOct 12, 2021
    risk 0.35cvss 5.3epss 0.01

    SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation could lead to exposure of some system…

  • CVE-2020-14130MedSep 16, 2021
    risk 0.35cvss 5.3epss 0.01

    Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809

  • CVE-2020-21356MedAug 6, 2021
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

  • CVE-2021-24374MedJun 21, 2021
    risk 0.35cvss 5.3epss 0.01

    The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the…

  • CVE-2021-22897MedJun 11, 2021
    risk 0.35cvss 5.3epss 0.03

    curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library,…

  • CVE-2021-20289MedMar 26, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's…

  • CVE-2020-1725MedJan 28, 2021
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.

  • CVE-2020-26650MedOct 22, 2020
    risk 0.35cvss 5.3epss 0.01

    AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php

  • CVE-2020-25073MedSep 2, 2020
    risk 0.35cvss 5.3epss 0.02

    FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and…

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-3315MedMay 6, 2020
    risk 0.35cvss 5.3epss 0.02

    Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles…