VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 143 of 187
  • CVE-2022-23490MedDec 16, 2022
    risk 0.28cvss 4.3epss 0.00

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update…

  • CVE-2022-42351MedDec 16, 2022
    risk 0.28cvss 4.3epss 0.01

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level confidentiality information.…

  • CVE-2022-46160MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.104, project level authorizations are not properly verified when accessing the project "homepage"/dashboards. Users not authorized to access a project…

  • CVE-2022-23473MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.148, Authorizations are not properly verified when accessing MediaWiki standalone resources. Users with read only permissions for pages are able to also…

  • CVE-2020-36610MedDec 8, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…

  • CVE-2022-4349MedDec 8, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…

  • CVE-2022-4090MedNov 24, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit…

  • CVE-2022-4014MedNov 16, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier…

  • CVE-2022-4013MedNov 16, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has…

  • CVE-2022-39340MedOct 25, 2022
    risk 0.28cvss 5.3epss 0.01

    OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA…

  • CVE-2022-3585MedOct 18, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is…

  • CVE-2022-3582MedOct 18, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument change password leads to cross-site request forgery. The attack…

  • CVE-2022-42724MedOct 10, 2022
    risk 0.28cvss 4.3epss 0.00

    app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

  • CVE-2021-40692MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient capability checks made it possible for teachers to download users outside of their courses.

  • CVE-2022-36109MedSep 9, 2022
    risk 0.28cvss 5.3epss 0.01

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access,…

  • CVE-2021-3763MedAug 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality…

  • CVE-2022-2095MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's…

  • CVE-2022-31190MedAug 1, 2022
    risk 0.28cvss 5.3epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL…

  • CVE-2022-31178MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.00

    eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are advised to upgrade. There are no known…

  • CVE-2022-31155MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.00

    Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’…