VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 115 of 187
  • CVE-2022-43515MedDec 5, 2022
    risk 0.35cvss 5.3epss 0.01

    Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be…

  • CVE-2022-45383MedNov 15, 2022
    risk 0.35cvss 6.5epss 0.01

    An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.

  • CVE-2022-3024MedSep 26, 2022
    risk 0.35cvss 5.4epss 0.00

    The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could…

  • CVE-2022-2597MedSep 5, 2022
    risk 0.35cvss 5.4epss 0.00

    The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

  • CVE-2022-35692MedAug 19, 2022
    risk 0.35cvss 5.3epss 0.01

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of…

  • CVE-2022-0594MedJul 25, 2022
    risk 0.35cvss 5.3epss 0.02

    The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve…

  • CVE-2022-31153MedJul 15, 2022
    risk 0.35cvss 6.5epss 0.01

    OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and…

  • CVE-2022-1944MedJun 6, 2022
    risk 0.35cvss 5.4epss 0.01

    When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers'…

  • CVE-2022-1753MedMay 17, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack…

  • CVE-2022-0574MedMay 16, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

  • CVE-2022-0866MedMay 10, 2022
    risk 0.35cvss 5.3epss 0.01

    This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field…

  • CVE-2022-1365MedApr 15, 2022
    risk 0.35cvss 6.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.

  • CVE-2022-0720MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked…

  • CVE-2022-0528MedMar 3, 2022
    risk 0.35cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

  • CVE-2021-3658MedMar 2, 2022
    risk 0.35cvss 6.5epss 0.01

    bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the…

  • CVE-2022-0577MedMar 2, 2022
    risk 0.35cvss 6.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

  • CVE-2022-0731MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2020-13676MedFeb 11, 2022
    risk 0.35cvss 6.5epss 0.01

    The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

  • CVE-2022-0273MedJan 30, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in Pypi calibreweb prior to 0.6.16.

  • CVE-2021-4194MedJan 6, 2022
    risk 0.35cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Access Control