VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 176 of 475
  • CVE-2025-21527MedJan 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-55996MedDec 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-product-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dreamfox Media Payment gateway per Product for…

  • CVE-2024-51516MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally.

  • CVE-2024-41918MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application…

  • CVE-2024-6180HigJul 9, 2024
    risk 0.40cvss 7.2epss 0.00

    The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all versions up to, and including, 2.2.15. This makes it possible for unauthenticated attackers to update plugin…

  • CVE-2024-1094HigJun 14, 2024
    risk 0.40cvss 7.3epss 0.01

    The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including,…

  • CVE-2024-23388MedJan 26, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

  • CVE-2024-0238MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.00

    The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

  • CVE-2023-39507MedAug 16, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.

  • CVE-2023-2796MedJul 10, 2023
    risk 0.40cvss 5.3epss 0.43

    The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

  • CVE-2023-2788MedJun 16, 2023
    risk 0.40cvss 6.2epss 0.01

    Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

  • CVE-2023-0291HigJun 9, 2023
    risk 0.40cvss 7.2epss 0.02

    The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated…

  • CVE-2022-2543MedSep 5, 2022
    risk 0.40cvss 6.1epss 0.01

    The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

  • CVE-2022-36836MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

  • CVE-2022-28789MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.

  • CVE-2021-24977MedFeb 28, 2022
    risk 0.40cvss 6.1epss 0.01

    The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation…

  • CVE-2021-20834MedOct 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions prior to 2.177.1 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

  • CVE-2021-20733MedJun 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

  • CVE-2021-25344MedMar 4, 2021
    risk 0.40cvss 6.2epss 0.00

    Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.

  • CVE-2020-10746MedOct 19, 2020
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a user authenticated to the local machine to perform all operations on the caches, including the…