VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,032)

page 19 of 502
  • CVE-2024-54369CriDec 16, 2024
    risk 0.59cvss 9.1epss 0.02

    Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

  • CVE-2022-46838CriDec 13, 2024
    risk 0.59cvss 9.1epss 0.01

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

  • CVE-2024-53810CriDec 6, 2024
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in N-Media Simple User Registration wp-registration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Simple User Registration: from n/a through <= 5.5.

  • CVE-2024-7475CriOct 29, 2024
    risk 0.59cvss 9.1epss 0.01

    An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user…

  • CVE-2024-38002CriOct 22, 2024
    risk 0.59cvss 9.0epss 0.01

    The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which…

  • CVE-2024-45168CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.

  • CVE-2024-43401CriAug 19, 2024
    risk 0.59cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights…

  • CVE-2023-39312CriJun 19, 2024
    risk 0.59cvss 9.1epss 0.01

    Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

  • CVE-2024-33565CriJun 9, 2024
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

  • CVE-2024-32948CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.01

    Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.

  • CVE-2023-36621CriNov 3, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

  • CVE-2023-44208CriOct 4, 2023
    risk 0.59cvss 9.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2023-41296CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.

  • CVE-2023-3124HigJun 7, 2023
    risk 0.59cvss 8.8epss 0.23

    The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2021-4357CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers…

  • CVE-2021-4356CriJun 7, 2023
    risk 0.59cvss 9.0epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action.…

  • CVE-2023-26957CriMar 9, 2023
    risk 0.59cvss 9.1epss 0.01

    onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

  • CVE-2022-39811CriJan 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to view pages that are not allowed, and modify the system…

  • CVE-2022-35293CriAug 10, 2022
    risk 0.59cvss 9.1epss 0.01

    Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

  • CVE-2022-1521CriJun 24, 2022
    risk 0.59cvss 9.1epss 0.01

    LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.