VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 363 of 464
  • CVE-2024-41729MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the…

  • CVE-2024-8427MedSep 6, 2024
    risk 0.28cvss 4.3epss 0.00

    The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all versions up to, and…

  • CVE-2024-44082MedSep 6, 2024
    risk 0.28cvss 4.3epss 0.01

    In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to…

  • CVE-2024-7380MedSep 5, 2024
    risk 0.28cvss 4.3epss 0.00

    The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to, and including, 8.7.3. This makes it possible for…

  • CVE-2024-5309MedSep 5, 2024
    risk 0.28cvss 5.4epss 0.00

    The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the fv_export_csv, reset_settings, save_settings, save_columns_settings, get_analytics_data,…

  • CVE-2024-6688MedAug 27, 2024
    risk 0.28cvss 4.3epss 0.00

    The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-6883MedAug 21, 2024
    risk 0.28cvss 4.3epss 0.00

    The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability check on the saveTimezoneString and some other functions in all versions up to and including…

  • CVE-2024-5941MedAug 20, 2024
    risk 0.28cvss 5.4epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This makes it possible for…

  • CVE-2024-42373MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically…

  • CVE-2024-41734MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

  • CVE-2024-39591MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.

  • CVE-2024-42377MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application

  • CVE-2024-7648MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.01

    The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with…

  • CVE-2024-7621MedAug 12, 2024
    risk 0.28cvss 5.4epss 0.00

    The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_wpfeedback_misc_options() function in all versions up to, and including, 4.0.2.…

  • CVE-2024-6987MedAug 8, 2024
    risk 0.28cvss 4.3epss 0.00

    The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with…

  • CVE-2024-6869MedAug 8, 2024
    risk 0.28cvss 5.4epss 0.00

    The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.3.52. This makes it possible for authenticated attackers, with…

  • CVE-2024-5331MedAug 1, 2024
    risk 0.28cvss 4.3epss 0.00

    The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.

  • CVE-2024-1804MedJul 27, 2024
    risk 0.28cvss 4.3epss 0.00

    The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with…

  • CVE-2024-6799MedJul 19, 2024
    risk 0.28cvss 4.3epss 0.00

    The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_module', 'deactivate_module', and 'install_module' functions in all versions up to, and including, 2.34.0. This…

  • CVE-2024-6599MedJul 18, 2024
    risk 0.28cvss 4.3epss 0.00

    The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with…