VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 91 of 464
  • CVE-2023-49979HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2024-28215HigMar 7, 2024
    risk 0.49cvss 7.5epss 0.01

    nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.

  • CVE-2023-6029HigJan 15, 2024
    risk 0.49cvss 7.5epss 0.00

    The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

  • CVE-2023-6383HigJan 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

  • CVE-2023-51650HigDec 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this…

  • CVE-2023-5949HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.

  • CVE-2023-39167HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

  • CVE-2023-46354HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of…

  • CVE-2023-44113HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-30581HigNov 23, 2023
    risk 0.49cvss 7.5epss 0.01

    The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definition. This vulnerability affects all users using the experimental policy mechanism in all active release lines: v16, v18 and, v20. …

  • CVE-2023-6038HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.04

    A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require…

  • CVE-2023-5454HigNov 6, 2023
    risk 0.49cvss 7.5epss 0.01

    The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.

  • CVE-2023-46352HigNov 2, 2023
    risk 0.49cvss 7.5epss 0.00

    In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can…

  • CVE-2023-5132HigOct 21, 2023
    risk 0.49cvss 7.5epss 0.01

    The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteRequest function in versions up to, and including, 6.0.1. This makes it possible for unauthenticated attackers with knowledge of an…

  • CVE-2022-4943HigOct 20, 2023
    risk 0.49cvss 7.5epss 0.01

    The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's…

  • CVE-2023-33915HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2023-39966HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data…

  • CVE-2023-37860HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.

  • CVE-2023-20899HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.01

    VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.

  • CVE-2023-30195HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can download personal informations without restriction formatted in json.