VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 380 of 464
  • CVE-2022-4103MedJan 9, 2023
    risk 0.28cvss 4.3epss 0.00

    The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any…

  • CVE-2022-3923MedJan 9, 2023
    risk 0.28cvss 4.3epss 0.00

    The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

  • CVE-2022-4124MedDec 19, 2022
    risk 0.28cvss 4.3epss 0.00

    The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them

  • CVE-2022-43482MedNov 18, 2022
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.

  • CVE-2022-41692MedNov 18, 2022
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.

  • CVE-2022-3920MedNov 16, 2022
    risk 0.28cvss 5.3epss 0.01

    HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.

  • CVE-2022-45399MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.

  • CVE-2022-45394MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.

  • CVE-2022-45390MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-2450MedNov 14, 2022
    risk 0.28cvss 4.3epss 0.00

    The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.

  • CVE-2022-3451MedNov 7, 2022
    risk 0.28cvss 4.3epss 0.00

    The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

  • CVE-2022-39340MedOct 25, 2022
    risk 0.28cvss 5.3epss 0.01

    OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA…

  • CVE-2022-39233MedOct 19, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration.…

  • CVE-2022-40316MedSep 30, 2022
    risk 0.28cvss 4.3epss 0.01

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

  • CVE-2022-2405MedSep 26, 2022
    risk 0.28cvss 4.3epss 0.00

    The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

  • CVE-2022-35249MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

  • CVE-2022-35247MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.

  • CVE-2022-39975MedSep 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via…

  • CVE-2022-41252MedSep 21, 2022
    risk 0.28cvss 4.3epss 0.01

    Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2022-41251MedSep 21, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.