VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 377 of 464
  • CVE-2023-41941MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.

  • CVE-2023-4059MedSep 4, 2023
    risk 0.28cvss 4.3epss 0.00

    The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

  • CVE-2023-4245MedAug 31, 2023
    risk 0.28cvss 4.3epss 0.01

    The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided…

  • CVE-2023-2174MedAug 31, 2023
    risk 0.28cvss 4.3epss 0.00

    The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-40344MedAug 16, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-4282MedAug 10, 2023
    risk 0.28cvss 5.4epss 0.01

    The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with…

  • CVE-2023-38989MedJul 31, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information.

  • CVE-2023-3403MedJul 18, 2023
    risk 0.28cvss 5.4epss 0.01

    The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-37950MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-37945MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.

  • CVE-2023-2562MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.00

    The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a…

  • CVE-2023-2561MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.00

    The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to…

  • CVE-2021-4388MedJul 1, 2023
    risk 0.28cvss 4.3epss 0.01

    The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it…

  • CVE-2023-1844MedJun 28, 2023
    risk 0.28cvss 4.3epss 0.01

    The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary…

  • CVE-2023-36002MedJun 27, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.

  • CVE-2023-2791MedJun 16, 2023
    risk 0.28cvss 4.3epss 0.00

    When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.

  • CVE-2023-2786MedJun 16, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

  • CVE-2023-2783MedJun 16, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.

  • CVE-2023-2284MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.00

    The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_switch_db function in versions up to, and including, 4.5.0. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2023-2261MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with subscriber-level access or higher,…