VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 239 of 475
  • CVE-2023-0404MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-0402MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…

  • CVE-2022-3961MedDec 19, 2022
    risk 0.35cvss 6.5epss 0.01

    The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.

  • CVE-2022-20941MedNov 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based…

  • CVE-2022-40223MedNov 8, 2022
    risk 0.35cvss 5.4epss 0.00

    Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.

  • CVE-2022-36404MedNov 3, 2022
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.

  • CVE-2022-3096MedOct 31, 2022
    risk 0.35cvss 5.4epss 0.00

    The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of…

  • CVE-2022-43421MedOct 19, 2022
    risk 0.35cvss 5.3epss 0.01

    A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value.

  • CVE-2022-3124MedOct 3, 2022
    risk 0.35cvss 5.3epss 0.07

    The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the…

  • CVE-2020-15338MedSep 29, 2022
    risk 0.35cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.

  • CVE-2020-15337MedSep 29, 2022
    risk 0.35cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.

  • CVE-2022-38512MedSep 22, 2022
    risk 0.35cvss 6.5epss 0.01

    The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via…

  • CVE-2022-41242MedSep 21, 2022
    risk 0.35cvss 5.4epss 0.01

    A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.

  • CVE-2022-2461MedSep 6, 2022
    risk 0.35cvss 5.3epss 0.04

    The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings…

  • CVE-2022-2373MedAug 29, 2022
    risk 0.35cvss 5.3epss 0.02

    The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

  • CVE-2022-38183MedAug 12, 2022
    risk 0.35cvss 6.5epss 0.01

    In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…

  • CVE-2022-31128MedAug 1, 2022
    risk 0.35cvss 5.4epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the REST API in Git repositories using the fine grained permissions. Users can…

  • CVE-2022-36896MedJul 27, 2022
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

  • CVE-2022-36888MedJul 27, 2022
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.

  • CVE-2022-31597MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of…