VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 49 of 464
  • CVE-2022-26423HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

  • CVE-2022-1070HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

  • CVE-2022-1066HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

  • CVE-2022-36921HigJul 27, 2022
    risk 0.53cvss 8.1epss 0.01

    A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-1903HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.09

    The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their…

  • CVE-2022-1572HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.01

    The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

  • CVE-2021-46820HigJun 16, 2022
    risk 0.53cvss 8.1epss 0.01

    Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php

  • CVE-2021-37764HigJun 16, 2022
    risk 0.53cvss 8.1epss 0.01

    Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.

  • CVE-2021-33013HigMay 13, 2022
    risk 0.53cvss 8.2epss 0.01

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.

  • CVE-2021-43938HigApr 29, 2022
    risk 0.53cvss 8.1epss 0.01

    Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.

  • CVE-2022-25342HigApr 20, 2022
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for…

  • CVE-2022-0229HigMar 21, 2022
    risk 0.53cvss 8.1epss 0.01

    The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options…

  • CVE-2021-41112HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing…

  • CVE-2022-21660HigFeb 9, 2022
    risk 0.53cvss 8.1epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as soon as possible. There are no…

  • CVE-2021-20873HigDec 28, 2021
    risk 0.53cvss 8.1epss 0.01

    Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are developed with Yappli versions since v7.3.6 and prior to v9.30.0, they are vulnerable to improper authorization in Custom URL Scheme…

  • CVE-2021-37572HigDec 26, 2021
    risk 0.53cvss 8.2epss 0.01

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Missing authorization).

  • CVE-2021-40501HigNov 10, 2021
    risk 0.53cvss 8.1epss 0.01

    SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system.…

  • CVE-2021-40884HigOct 11, 2021
    risk 0.53cvss 8.1epss 0.01

    Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.

  • CVE-2021-24639HigSep 20, 2021
    risk 0.53cvss 8.1epss 0.01

    The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

  • CVE-2021-40379HigSep 1, 2021
    risk 0.53cvss 7.5epss 0.22

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.