VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 9 of 463
  • CVE-2023-5877CriJan 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private…

  • CVE-2023-48417CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

  • CVE-2023-49654CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.

  • CVE-2023-20252CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper…

  • CVE-2023-43135CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2023-43134CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2023-39073CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.

  • CVE-2023-36140CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.00

    In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

  • CVE-2023-26301CriJul 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of authentication with certain endpoints.

  • CVE-2023-3076CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.02

    The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

  • CVE-2021-4381CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for…

  • CVE-2021-4370CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible…

  • CVE-2021-4368CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for…

  • CVE-2021-4362CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated…

  • CVE-2021-4347CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any…

  • CVE-2021-4346CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any…

  • CVE-2021-4343CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible…

  • CVE-2021-4341CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for…

  • CVE-2020-36719CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for…

  • CVE-2019-25141CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated…