VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 92 of 464
  • CVE-2023-35940HigJul 5, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.

  • CVE-2023-30586HigJul 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API…

  • CVE-2021-4355HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7.…

  • CVE-2021-4348HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to change plugin settings and…

  • CVE-2021-4339HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for…

  • CVE-2020-36696HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download…

  • CVE-2023-2480HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications

  • CVE-2023-33252HigMay 21, 2023
    risk 0.49cvss 7.5epss 0.01

    iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

  • CVE-2023-27963HigMay 8, 2023
    risk 0.49cvss 7.5epss 0.01

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. A shortcut may be able to use sensitive data with certain actions without…

  • CVE-2022-48350HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-48302HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48166HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.03

    An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

  • CVE-2021-31576HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In Boa, there is a possible information disclosure due to a missing permission check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…

  • CVE-2022-43581HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805.

  • CVE-2022-44009HigDec 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive Information.

  • CVE-2022-24190HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.01

    The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a…

  • CVE-2022-44549HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.

  • CVE-2021-28052HigSep 26, 2022
    risk 0.49cvss 7.5epss 0.01

    A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Also, a tenant user (non-administrator) may view configuration in another tenant…

  • CVE-2022-2987HigSep 26, 2022
    risk 0.49cvss 7.5epss 0.00

    The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP…

  • CVE-2022-36091HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.01

    XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 and 14.2. This includes private personal…