VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 113 of 187
  • CVE-2024-45131MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.00

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a…

  • CVE-2024-45128MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a…

  • CVE-2024-7048MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.00

    In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By…

  • CVE-2024-45037MedAug 27, 2024
    risk 0.35cvss 6.4epss 0.00

    The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own applications which are converted to AWS CloudFormation templates during deployment to a customer’s AWS account. CDK contains…

  • CVE-2024-31403MedJun 11, 2024
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.

  • CVE-2024-3404MedJun 6, 2024
    risk 0.35cvss 6.5epss 0.01

    In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users,…

  • CVE-2024-3504MedJun 6, 2024
    risk 0.35cvss 6.5epss 0.00

    An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is…

  • CVE-2024-3722MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.00

    The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions up to, and including, 2.3.6.18. This makes it possible for authenticated attackers, with subscriber-level access…

  • CVE-2024-29834MedApr 2, 2024
    risk 0.35cvss 6.4epss 0.01

    This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the tenant admin role or…

  • CVE-2024-2557MedMar 17, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin.php. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit…

  • CVE-2023-50726MedMar 13, 2024
    risk 0.35cvss 6.4epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defined manifests. Use of the feature should generally be limited to highly-trusted…

  • CVE-2024-1479MedMar 13, 2024
    risk 0.35cvss 5.3epss 0.01

    The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_display function. This makes it possible for authenticated attackers with contributor access and above to view the contents of draft,…

  • CVE-2024-25604MedFeb 20, 2024
    risk 0.35cvss 6.5epss 0.00

    Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user…

  • CVE-2024-21987MedFeb 16, 2024
    risk 0.35cvss 5.4epss 0.00

    SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system logging configuration settings

  • CVE-2023-6152MedFeb 13, 2024
    risk 0.35cvss 5.4epss 0.01

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

  • CVE-2024-22208MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. The phpMyFAQ…

  • CVE-2023-49273MedDec 12, 2023
    risk 0.35cvss 5.4epss 0.00

    Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low privileges (Editor, etc.) are able to access some unintended endpoints. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for…

  • CVE-2023-42575MedDec 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.

  • CVE-2023-5799MedNov 20, 2023
    risk 0.35cvss 5.4epss 0.01

    The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

  • CVE-2023-5509MedNov 20, 2023
    risk 0.35cvss 5.4epss 0.01

    The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.