VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 8 of 463
  • CVE-2019-25217CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on the switch_php function called via the…

  • CVE-2018-25105CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and…

  • CVE-2024-21216CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2024-9707CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.09

    The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated…

  • CVE-2024-8289CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.01

    The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability check on the update_item_permissions_check and…

  • CVE-2024-4259CriSep 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users. This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (TahsilatService): before V1.0.7.

  • CVE-2024-4428CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.

  • CVE-2024-6806CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.01

    The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.

  • CVE-2024-6636CriJul 20, 2024
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to…

  • CVE-2024-6303CriJun 25, 2024
    risk 0.64cvss 9.9epss 0.00

    Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords,…

  • CVE-2024-4898CriJun 12, 2024
    risk 0.64cvss 9.8epss 0.04

    The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers…

  • CVE-2024-31244CriJun 9, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

  • CVE-2024-36246CriMay 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

  • CVE-2024-27939CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.

  • CVE-2023-49742CriApr 18, 2024
    risk 0.64cvss 9.9epss 0.01

    Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.

  • CVE-2024-25912CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

  • CVE-2024-29241CriMar 28, 2024
    risk 0.64cvss 9.9epss 0.01

    Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via…

  • CVE-2024-23752CriJan 22, 2024
    risk 0.64cvss 9.8epss 0.01

    GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of…

  • CVE-2023-34063CriJan 16, 2024
    risk 0.64cvss 9.9epss 0.01

    Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

  • CVE-2023-47458CriJan 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.