VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 32 of 40
  • CVE-2022-40316MedSep 30, 2022
    risk 0.28cvss 4.3epss 0.01

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

  • CVE-2022-1875MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1637MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1498MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1488MedJul 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

  • CVE-2020-36532MedJun 7, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in Klapp App and classified as problematic. This vulnerability affects unknown code of the component Authorization. The manipulation leads to information disclosure (Credentials). The attack can be initiated remotely. It is recommended to upgrade…

  • CVE-2022-27331MedApr 27, 2022
    risk 0.28cvss 4.3epss 0.01

    An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.

  • CVE-2022-25041MedMar 23, 2022
    risk 0.28cvss 4.3epss 0.01

    OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.

  • CVE-2020-4989MedMar 15, 2022
    risk 0.28cvss 4.3epss 0.01

    IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707.

  • CVE-2021-24868MedFeb 1, 2022
    risk 0.28cvss 4.3epss 0.01

    The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.

  • CVE-2021-38004MedNov 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-40496MedOct 12, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial…

  • CVE-2021-33330MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.01

    Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive…

  • CVE-2021-32731MedJul 1, 2021
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on…

  • CVE-2021-24001MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. This vulnerability affects Firefox < 88.

  • CVE-2020-26272MedJan 28, 2021
    risk 0.28cvss 5.4epss 0.02

    The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main process to a subframe in the renderer process, through…

  • CVE-2020-26086MedNov 6, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storage of sensitive…

  • CVE-2020-6490MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6442MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-4633MedJan 28, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 170007.