VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 94 of 464
  • CVE-2021-27857HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.02

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly…

  • CVE-2021-41066HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user…

  • CVE-2021-20865HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.

  • CVE-2021-20835HigNov 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches…

  • CVE-2021-42359HigNov 5, 2021
    risk 0.49cvss 7.5epss 0.04

    WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for…

  • CVE-2018-25019HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

  • CVE-2015-20067HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.08

    The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

  • CVE-2021-37738HigOct 15, 2021
    risk 0.49cvss 7.5epss 0.01

    A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1.…

  • CVE-2021-41077HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.01

    The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not specified by the customer-controlled .travis.yml file. In particular, the desired behavior (if .travis.yml has been created locally by…

  • CVE-2021-30874HigAug 24, 2021
    risk 0.49cvss 7.5epss 0.01

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.

  • CVE-2020-18757HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.

  • CVE-2020-22176HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.

  • CVE-2018-10865HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.

  • CVE-2020-18888HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.

  • CVE-2021-20693HigApr 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

  • CVE-2021-28669HigMar 29, 2021
    risk 0.49cvss 7.5epss 0.01

    Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative rights.

  • CVE-2020-16260HigOct 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

  • CVE-2020-26598HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized actor to kill a TCP connection. The LG ID is LVE-SMP-200023 (October 2020).

  • CVE-2020-14520HigJul 31, 2020
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13).

  • CVE-2020-14969HigJun 22, 2020
    risk 0.49cvss 7.5epss 0.01

    app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.