VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 232 of 475
  • CVE-2024-4102MedJul 9, 2024
    risk 0.35cvss 5.4epss 0.00

    The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above,…

  • CVE-2024-37172MedJul 9, 2024
    risk 0.35cvss 5.4epss 0.00

    SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity.

  • CVE-2024-37542MedJul 6, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

  • CVE-2024-36995MedJul 1, 2024
    risk 0.35cvss 5.4epss 0.00

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could create experimental items.

  • CVE-2024-6375MedJul 1, 2024
    risk 0.35cvss 5.4epss 0.00

    A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server…

  • CVE-2024-5710MedJun 27, 2024
    risk 0.35cvss 6.5epss 0.00

    berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding…

  • CVE-2024-3627MedJun 20, 2024
    risk 0.35cvss 5.4epss 0.00

    The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This…

  • CVE-2023-38394MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

  • CVE-2023-39310MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.

  • CVE-2023-36676MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

  • CVE-2023-39990MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

  • CVE-2023-35050MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.

  • CVE-2023-44151MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.

  • CVE-2023-44148MedJun 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.

  • CVE-2023-51497MedJun 14, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.

  • CVE-2023-51516MedJun 14, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.

  • CVE-2023-36695MedJun 14, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

  • CVE-2023-40672MedJun 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

  • CVE-2023-38395MedJun 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

  • CVE-2023-52177MedJun 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.