VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 48 of 464
  • CVE-2023-5905HigJan 15, 2024
    risk 0.53cvss 8.1epss 0.01

    The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished…

  • CVE-2023-48222HigNov 16, 2023
    risk 0.53cvss 8.1epss 0.00

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the URL path, which would allow…

  • CVE-2023-6020HigNov 16, 2023
    risk 0.53cvss 7.5epss 0.15

    LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.

  • CVE-2023-43885HigNov 7, 2023
    risk 0.53cvss 8.1epss 0.01

    Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.

  • CVE-2022-3007HigOct 31, 2023
    risk 0.53cvss 8.1epss 0.00

    The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Device Firmware Update (DFU) which is used for performing Over-The-Air (OTA) firmware updates on the Bluetooth Low Energy (BLE) devices. An unauthenticated…

  • CVE-2023-30969HigOct 26, 2023
    risk 0.53cvss 8.2epss 0.00

    The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.

  • CVE-2023-4606HigOct 25, 2023
    risk 0.53cvss 8.1epss 0.00

    An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

  • CVE-2023-43652HigSep 27, 2023
    risk 0.53cvss 8.2epss 0.01

    JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be considered public knowledge…

  • CVE-2023-39438HigAug 15, 2023
    risk 0.53cvss 8.1epss 0.00

    A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons…

  • CVE-2023-37862HigAug 9, 2023
    risk 0.53cvss 8.2epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.

  • CVE-2023-34463HigJun 26, 2023
    risk 0.53cvss 8.1epss 0.01

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade.…

  • CVE-2021-4383HigJun 7, 2023
    risk 0.53cvss 8.1epss 0.01

    The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as…

  • CVE-2023-2545HigMay 31, 2023
    risk 0.53cvss 8.1epss 0.01

    The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with…

  • CVE-2023-25552HigApr 18, 2023
    risk 0.53cvss 8.1epss 0.01

    A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products:…

  • CVE-2023-27701HigMar 28, 2023
    risk 0.53cvss 8.1epss 0.01

    MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.

  • CVE-2023-1262HigMar 21, 2023
    risk 0.53cvss 8.2epss 0.00

    Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.

  • CVE-2023-1261HigMar 21, 2023
    risk 0.53cvss 8.2epss 0.00

    Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.

  • CVE-2022-45636HigMar 21, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.

  • CVE-2022-3999HigDec 12, 2022
    risk 0.53cvss 8.1epss 0.00

    The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

  • CVE-2022-26423HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.