VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 376 of 464
  • CVE-2023-50779MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.

  • CVE-2023-50767MedDec 13, 2023
    risk 0.28cvss 5.4epss 0.00

    Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.

  • CVE-2023-5714MedDec 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with…

  • CVE-2023-5713MedDec 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers,…

  • CVE-2023-5712MedDec 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers,…

  • CVE-2023-5711MedDec 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with…

  • CVE-2023-5710MedDec 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with…

  • CVE-2023-37890MedNov 30, 2023
    risk 0.28cvss 4.3epss 0.01

    Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress…

  • CVE-2023-49674MedNov 29, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.

  • CVE-2023-5737MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.00

    The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

  • CVE-2023-5525MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.00

    The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.

  • CVE-2023-47757MedNov 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth allows Accessing Functionality Not Properly Constrained by ACLs, Cross-Site Request…

  • CVE-2023-5251MedOct 30, 2023
    risk 0.28cvss 5.4epss 0.00

    The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it…

  • CVE-2023-46652MedOct 25, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins.

  • CVE-2023-4947MedOct 20, 2023
    risk 0.28cvss 4.3epss 0.00

    The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with…

  • CVE-2023-44689MedOct 11, 2023
    risk 0.28cvss 4.3epss 0.00

    e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary…

  • CVE-2023-5331MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.

  • CVE-2023-4948MedSep 14, 2023
    risk 0.28cvss 4.3epss 0.00

    The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_cvr_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with…

  • CVE-2023-4792MedSep 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for…

  • CVE-2023-41947MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to Frugal Testing using attacker-specified credentials.