VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 167 of 213
  • CVE-2023-3253MedAug 29, 2023
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list of all the users available in the application.

  • CVE-2023-4242MedAug 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to obtain sensitive…

  • CVE-2023-3582MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have access to, 

  • CVE-2023-2576MedJul 13, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected…

  • CVE-2023-30955MedJun 29, 2023
    risk 0.28cvss 4.3epss 0.00

    A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a…

  • CVE-2023-29296MedJun 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to modify a minor…

  • CVE-2023-29295MedJun 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor…

  • CVE-2023-29288MedJun 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A privileged attacker could leverage this vulnerability to modify a minor…

  • CVE-2023-1779MedJun 6, 2023
    risk 0.28cvss 4.3epss 0.01

    Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another…

  • CVE-2023-25749MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. Firefox will now confirm with users that they want to launch an external application before doing so. *This bug only affects Firefox for…

  • CVE-2023-34219MedMay 31, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

  • CVE-2023-24600MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.

  • CVE-2023-1158MedMay 24, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

  • CVE-2023-27920MedMay 23, 2023
    risk 0.28cvss 4.3epss 0.02

    Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system date/time of the affected product.

  • CVE-2023-27384MedMay 23, 2023
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.

  • CVE-2023-29927MedMay 16, 2023
    risk 0.28cvss 4.3epss 0.00

    Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privileged Sage users, particularly those on a workstation setup in the "Windows Peer-to-Peer Network" or "Client Server Network" Sage 300 configurations, could recover…

  • CVE-2023-28357MedMay 11, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a…

  • CVE-2021-44465MedApr 25, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.

  • CVE-2023-2020MedApr 18, 2023
    risk 0.28cvss 4.3epss 0.00

    Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.

  • CVE-2023-1417MedApr 5, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.