VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,450)

page 300 of 473
  • CVE-2023-5611MedNov 27, 2023
    risk 0.34cvss 5.3epss 0.00

    The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

  • CVE-2023-6001MedNov 8, 2023
    risk 0.34cvss 5.3epss 0.01

    Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

  • CVE-2023-5533MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.01

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unauthenticated attackers to perform some of…

  • CVE-2023-4668MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.01

    The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and…

  • CVE-2023-3998MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.00

    The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of…

  • CVE-2023-3869MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.00

    The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the…

  • CVE-2021-4353MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.01

    The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function which makes makes it possible for unauthenticated attackers…

  • CVE-2023-45370MedOct 9, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. SportsTeams: Special:SportsManagerLogo and Special:SportsTeamsManagerLogo do not check for the sportsteamsmanager user right, and…

  • CVE-2023-40376MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.

  • CVE-2023-3213MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.00

    The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive…

  • CVE-2023-3770MedOct 2, 2023
    risk 0.34cvss 5.3epss 0.00

     Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the affected device is located to use the discovery port protocol (1925/UDP) to obtain device-specific information without the need for authentication.

  • CVE-2023-40040MedSep 11, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations. NOTE: this is only exploitable on Android…

  • CVE-2023-41046MedSep 1, 2023
    risk 0.34cvss 6.3epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity code without having script right by creating an XClass with a property of type "TextArea" and content type "VelocityCode" or…

  • CVE-2023-23763MedSep 1, 2023
    risk 0.34cvss 5.3epss 0.01

    An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private. This vulnerability affected all versions of GitHub…

  • CVE-2023-36607MedJun 29, 2023
    risk 0.34cvss 5.3epss 0.00

    The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.

  • CVE-2022-48491MedJun 19, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time.

  • CVE-2023-34165MedJun 16, 2023
    risk 0.34cvss 5.3epss 0.00

    Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.

  • CVE-2023-2066MedJun 9, 2023
    risk 0.34cvss 6.3epss 0.01

    The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings',…

  • CVE-2023-30521MedApr 12, 2023
    risk 0.34cvss 5.3epss 0.01

    A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

  • CVE-2023-30519MedApr 12, 2023
    risk 0.34cvss 5.3epss 0.00

    A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.