VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 504 of 506
  • CVE-2024-45307HigSep 3, 2024
    risk 0.00cvss 8.8epss 0.00

    SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of…

  • CVE-2024-45058HigAug 28, 2024
    risk 0.00cvss 8.1epss 0.01

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to…

  • CVE-2024-44069HigAug 19, 2024
    risk 0.00cvss 7.5epss 0.00

    Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value…

  • CVE-2024-37903HigJul 5, 2024
    risk 0.00cvss 8.2epss 0.01

    Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining…

  • CVE-2024-36113MedJul 3, 2024
    risk 0.00cvss 4.9epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in…

  • CVE-2024-37317MedJun 14, 2024
    risk 0.00cvss 4.6epss 0.00

    The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the…

  • CVE-2024-37314LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.

  • CVE-2024-4520HigJun 4, 2024
    risk 0.00cvss 7.5epss 0.01

    An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the…

  • CVE-2024-32466LowApr 18, 2024
    risk 0.00cvss 2.7epss 0.00

    Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user…

  • CVE-2024-2216HigMar 6, 2024
    risk 0.00cvss 8.8epss 0.01

    A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test…

  • CVE-2024-21630MedJan 25, 2024
    risk 0.00cvss 4.3epss 0.00

    Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be…

  • CVE-2023-50976CriDec 18, 2023
    risk 0.00cvss 9.8epss 0.01

    Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.

  • CVE-2023-43194MedNov 2, 2023
    risk 0.00cvss 5.3epss 0.01

    Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.

  • CVE-2023-5862LowOct 31, 2023
    risk 0.00cvss 3.3epss 0.00

    Missing Authorization in GitHub repository hamza417/inure prior to Build95.

  • CVE-2023-5321MedSep 30, 2023
    risk 0.00cvss 5.5epss 0.00

    Missing Authorization in GitHub repository hamza417/inure prior to build94.

  • CVE-2023-4104MedSep 11, 2023
    risk 0.00cvss 5.5epss 0.00

    An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN…

  • CVE-2023-41908MedSep 5, 2023
    risk 0.00cvss 5.3epss 0.00

    Cerebrate before 1.15 lacks the Secure attribute for the session cookie.

  • CVE-2023-4434MedAug 20, 2023
    risk 0.00cvss 6.1epss 0.00

    Missing Authorization in GitHub repository hamza417/inure prior to build88.

  • CVE-2023-40216MedAug 10, 2023
    risk 0.00cvss 5.5epss 0.00

    OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.

  • CVE-2023-38494MedAug 4, 2023
    risk 0.00cvss 5.9epss 0.00

    MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.