VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 374 of 464
  • CVE-2023-4728MedMar 12, 2024
    risk 0.28cvss 4.3epss 0.00

    The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with…

  • CVE-2023-4627MedMar 12, 2024
    risk 0.28cvss 4.3epss 0.00

    The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to…

  • CVE-2024-27900MedMar 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.

  • CVE-2024-1124MedMar 9, 2024
    risk 0.28cvss 4.3epss 0.00

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for…

  • CVE-2024-28159MedMar 6, 2024
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.

  • CVE-2024-1771MedMar 6, 2024
    risk 0.28cvss 4.3epss 0.00

    The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions up to, and including, 2.1.59. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2024-23493MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 

  • CVE-2024-1390MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.01

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and…

  • CVE-2024-1337MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.00

    The SKT Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveSktbuilderPageData' function in all versions up to, and including, 4.1. This makes it possible for authenticated attackers, with subscriber…

  • CVE-2024-1288MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it possible for authenticated…

  • CVE-2024-1133MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A content due to a missing capability check when interacting with questions in all versions up to, and including, 2.6.0. This makes it possible for…

  • CVE-2023-51692MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.

  • CVE-2024-1861MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.00

    The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_truncate_scan_table() function in all versions up to, and…

  • CVE-2024-1388MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.00

    The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_customizer_options() function in all versions up to, and including, 1.3.13. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2024-1778MedFeb 23, 2024
    risk 0.28cvss 4.3epss 0.00

    The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for…

  • CVE-2023-4895MedFeb 22, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access…

  • CVE-2024-0593MedFeb 21, 2024
    risk 0.28cvss 5.3epss 0.01

    The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch…

  • CVE-2024-25643MedFeb 13, 2024
    risk 0.28cvss 4.3epss 0.00

    The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access information that the user should…

  • CVE-2024-24741MedFeb 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to read some sensitive…

  • CVE-2024-0595MedFeb 10, 2024
    risk 0.28cvss 4.3epss 0.00

    The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for…