CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 115 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43515 | Med | 0.35 | 5.3 | 0.01 | Dec 5, 2022 | Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be… | ||
| CVE-2022-45383 | Med | 0.35 | 6.5 | 0.01 | Nov 15, 2022 | An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission. | ||
| CVE-2022-3024 | Med | 0.35 | 5.4 | 0.00 | Sep 26, 2022 | The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could… | ||
| CVE-2022-2597 | Med | 0.35 | 5.4 | 0.00 | Sep 5, 2022 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts | ||
| CVE-2022-35692 | Med | 0.35 | 5.3 | 0.01 | Aug 19, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of… | ||
| CVE-2022-0594 | Med | 0.35 | 5.3 | 0.02 | Jul 25, 2022 | The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve… | ||
| CVE-2022-31153 | Med | 0.35 | 6.5 | 0.01 | Jul 15, 2022 | OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and… | ||
| CVE-2022-1944 | Med | 0.35 | 5.4 | 0.01 | Jun 6, 2022 | When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers'… | ||
| CVE-2022-1753 | Med | 0.35 | 5.4 | 0.01 | May 17, 2022 | A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack… | ||
| CVE-2022-0574 | Med | 0.35 | 6.5 | 0.01 | May 16, 2022 | Improper Access Control in GitHub repository publify/publify prior to 9.2.8. | ||
| CVE-2022-0866 | Med | 0.35 | 5.3 | 0.01 | May 10, 2022 | This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field… | ||
| CVE-2022-1365 | Med | 0.35 | 6.5 | 0.01 | Apr 15, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5. | ||
| CVE-2022-0720 | Med | 0.35 | 5.4 | 0.01 | Mar 28, 2022 | The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked… | ||
| CVE-2022-0528 | Med | 0.35 | 6.5 | 0.01 | Mar 3, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1. | ||
| CVE-2021-3658 | Med | 0.35 | 6.5 | 0.01 | Mar 2, 2022 | bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the… | ||
| CVE-2022-0577 | Med | 0.35 | 6.5 | 0.01 | Mar 2, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1. | ||
| CVE-2022-0731 | Med | 0.35 | 6.5 | 0.01 | Feb 23, 2022 | Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0. | ||
| CVE-2020-13676 | Med | 0.35 | 6.5 | 0.01 | Feb 11, 2022 | The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. | ||
| CVE-2022-0273 | Med | 0.35 | 6.5 | 0.01 | Jan 30, 2022 | Improper Access Control in Pypi calibreweb prior to 0.6.16. | ||
| CVE-2021-4194 | Med | 0.35 | 6.5 | 0.01 | Jan 6, 2022 | bookstack is vulnerable to Improper Access Control |
- risk 0.35cvss 5.3epss 0.01
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be…
- risk 0.35cvss 6.5epss 0.01
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.
- risk 0.35cvss 5.4epss 0.00
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could…
- risk 0.35cvss 5.4epss 0.00
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts
- risk 0.35cvss 5.3epss 0.01
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of…
- risk 0.35cvss 5.3epss 0.02
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve…
- risk 0.35cvss 6.5epss 0.01
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and…
- risk 0.35cvss 5.4epss 0.01
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers'…
- risk 0.35cvss 5.4epss 0.01
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack…
- risk 0.35cvss 6.5epss 0.01
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
- risk 0.35cvss 5.3epss 0.01
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field…
- risk 0.35cvss 6.5epss 0.01
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
- risk 0.35cvss 5.4epss 0.01
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked…
- risk 0.35cvss 6.5epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
- risk 0.35cvss 6.5epss 0.01
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the…
- risk 0.35cvss 6.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
- risk 0.35cvss 6.5epss 0.01
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
- risk 0.35cvss 6.5epss 0.01
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
- risk 0.35cvss 6.5epss 0.01
Improper Access Control in Pypi calibreweb prior to 0.6.16.
- risk 0.35cvss 6.5epss 0.01
bookstack is vulnerable to Improper Access Control