VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 12 of 463
  • CVE-2018-21042CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).

  • CVE-2020-11514CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.09

    The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

  • CVE-2016-11036CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

  • CVE-2019-12498CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

  • CVE-2020-10257CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.09

    The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…

  • CVE-2013-3960CriJan 24, 2020
    risk 0.64cvss 9.9epss 0.02

    Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass

  • CVE-2019-15932CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp has Incorrect Access Control.

  • CVE-2019-13547CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.

  • CVE-2019-1010152CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.

  • CVE-2019-1010150CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.

  • CVE-2019-1010149CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.

  • CVE-2019-6580CriJun 12, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions <…

  • CVE-2018-4059CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.02

    An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN…

  • CVE-2018-18996CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.02

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.

  • CVE-2019-5886CriJan 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to database.php during system…

  • CVE-2018-16591CriSep 10, 2018
    risk 0.64cvss 9.8epss 0.02

    FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.

  • CVE-2018-11541CriJul 9, 2018
    risk 0.64cvss 9.8epss 0.02

    A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to…

  • CVE-2018-8755CriJun 25, 2018
    risk 0.64cvss 9.8epss 0.01

    NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downloading this file, an attacker can access the admin password, WPA key, and any config information of the device.

  • CVE-2018-10251CriMay 4, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full…

  • CVE-2018-0015CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Agent is executing. If…