VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 116 of 187
  • CVE-2021-41013MedDec 8, 2021
    risk 0.35cvss 5.3epss 0.01

    An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.

  • CVE-2021-43781MedDec 6, 2021
    risk 0.35cvss 6.4epss 0.01

    Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable…

  • CVE-2021-3992MedDec 1, 2021
    risk 0.35cvss 6.5epss 0.01

    kimai2 is vulnerable to Improper Access Control

  • CVE-2021-24842MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

  • CVE-2021-43560MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

  • CVE-2021-25973MedNov 2, 2021
    risk 0.35cvss 6.5epss 0.01

    In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

  • CVE-2021-24757MedNov 1, 2021
    risk 0.35cvss 5.3epss 0.01

    The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

  • CVE-2021-20803MedOct 13, 2021
    risk 0.35cvss 5.4epss 0.01

    Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.

  • CVE-2021-40456MedOct 13, 2021
    risk 0.35cvss 5.3epss 0.02

    Windows AD FS Security Feature Bypass Vulnerability

  • CVE-2021-42137MedOct 11, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.

  • CVE-2021-22262MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and…

  • CVE-2019-16651MedSep 20, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN…

  • CVE-2021-28567MedSep 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin…

  • CVE-2021-35949MedSep 7, 2021
    risk 0.35cvss 5.3epss 0.01

    The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.

  • CVE-2021-39119MedSep 1, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected…

  • CVE-2021-34434MedAug 30, 2021
    risk 0.35cvss 5.3epss 0.01

    In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.

  • CVE-2021-22256MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

  • CVE-2021-37598MedAug 19, 2021
    risk 0.35cvss 5.3epss 0.02

    WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

  • CVE-2021-27793MedAug 12, 2021
    risk 0.35cvss 5.3epss 0.01

    ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the…

  • CVE-2020-28397MedAug 10, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl.…