VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 240 of 475
  • CVE-2022-20736MedJun 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to…

  • CVE-2022-30955MedMay 17, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-30954MedMay 17, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

  • CVE-2021-44055MedMay 5, 2022
    risk 0.35cvss 5.3epss 0.01

    An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability…

  • CVE-2022-1511MedApr 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

  • CVE-2022-0398MedApr 25, 2022
    risk 0.35cvss 5.4epss 0.00

    The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to…

  • CVE-2022-1054MedApr 18, 2022
    risk 0.35cvss 5.3epss 0.04

    The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name,…

  • CVE-2022-0919MedApr 11, 2022
    risk 0.35cvss 5.3epss 0.01

    The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email…

  • CVE-2022-0837MedApr 4, 2022
    risk 0.35cvss 5.4epss 0.01

    The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment…

  • CVE-2022-28134MedMar 29, 2022
    risk 0.35cvss 5.4epss 0.01

    Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.

  • CVE-2021-24950MedMar 14, 2022
    risk 0.35cvss 5.4epss 0.01

    The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before…

  • CVE-2022-0932MedMar 11, 2022
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.

  • CVE-2022-26104MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.

  • CVE-2022-26103MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

  • CVE-2022-26102MedMar 10, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized…

  • CVE-2021-25042MedFeb 28, 2022
    risk 0.35cvss 5.4epss 0.01

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address…

  • CVE-2022-24594MedFeb 25, 2022
    risk 0.35cvss 5.3epss 0.01

    In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.

  • CVE-2022-25355MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.01

    EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.

  • CVE-2022-0579MedFeb 14, 2022
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

  • CVE-2021-25018MedFeb 14, 2022
    risk 0.35cvss 5.4epss 0.01

    The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could…