VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 73 of 464
  • CVE-2023-5425HigOct 28, 2023
    risk 0.50cvss 8.8epss 0.01

    The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible for…

  • CVE-2023-5311HigOct 25, 2023
    risk 0.50cvss 8.8epss 0.01

    The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-43700HigOct 9, 2023
    risk 0.50cvss 7.7epss 0.01

    Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.

  • CVE-2023-33265HigJul 18, 2023
    risk 0.50cvss 8.8epss 0.01

    In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.

  • CVE-2023-3713HigJul 18, 2023
    risk 0.50cvss 8.8epss 0.01

    The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with…

  • CVE-2022-4950HigJun 7, 2023
    risk 0.50cvss 8.8epss 0.01

    Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

  • CVE-2022-30951HigMay 17, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.

  • CVE-2022-22111HigJan 5, 2022
    risk 0.50cvss 8.8epss 0.01

    In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the…

  • CVE-2021-39236HigNov 19, 2021
    risk 0.50cvss 8.8epss 0.03

    In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

  • CVE-2021-21695HigNov 4, 2021
    risk 0.50cvss 8.8epss 0.02

    FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21326HigMar 8, 2021
    risk 0.50cvss 7.7epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems…

  • CVE-2020-26832HigDec 9, 2020
    risk 0.50cvss 7.6epss 0.02

    SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC…

  • CVE-2020-23489HigNov 16, 2020
    risk 0.50cvss 8.8epss 0.02

    The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.

  • CVE-2020-6168HigJan 9, 2020
    risk 0.50cvss 7.6epss 0.02

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the…

  • CVE-2019-10339HigJun 11, 2019
    risk 0.50cvss 8.8epss 0.02

    A missing permission check in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed users with Overall/Read access to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.

  • CVE-2019-10147HigJun 3, 2019
    risk 0.50cvss 7.7epss 0.00

    rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by cgroups during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to…

  • CVE-2019-10145HigJun 3, 2019
    risk 0.50cvss 7.7epss 0.00

    rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp filtering during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw…

  • CVE-2019-10301HigApr 18, 2019
    risk 0.50cvss 8.8epss 0.01

    A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained…

  • CVE-2018-17490HigMar 21, 2019
    risk 0.50cvss 7.7epss 0.00

    EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will.

  • CVE-2019-1003025HigFeb 20, 2019
    risk 0.50cvss 8.8epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCloudFoundryPushDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs…