VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,734)

page 182 of 187
  • CVE-2024-32470MedApr 18, 2024
    risk 0.00cvss 6.5epss 0.01

    Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was introduced in v3.57.2 and immediately fixed in v3.57.4.

  • CVE-2024-22412LowMar 18, 2024
    risk 0.00cvss 2.4epss 0.01

    ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. Query caching bypasses the role based access controls and the policies being…

  • CVE-2024-24761HigMar 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it is possible to restrict to up-to-date…

  • CVE-2024-26145MedFeb 21, 2024
    risk 0.00cvss 6.5epss 0.00

    Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a request to update their attendance. This problem is resolved in commit…

  • CVE-2023-46241CriFeb 21, 2024
    risk 0.00cvss 9.0epss 0.01

    `discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's Discourse account. Sites that have configured their application's account type to…

  • CVE-2024-24573HigJan 31, 2024
    risk 0.00cvss 8.8epss 0.01

    facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint server/fm-modules/facileManager/ajax/processPost.php. It was found…

  • CVE-2023-52077HigDec 27, 2023
    risk 0.00cvss 8.9epss 0.01

    Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as…

  • CVE-2022-39337HigDec 22, 2023
    risk 0.00cvss 7.5epss 0.01

    Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke interfaces without…

  • CVE-2023-48712HigNov 24, 2023
    risk 0.00cvss 7.1epss 0.01

    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a non-admin user's account. Limited users can impersonate another user's account if only single-factor authentication is configured.…

  • CVE-2023-46139MedOct 31, 2023
    risk 0.00cvss 5.0epss 0.00

    KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infected with a malware whose app signing block specially constructed, it can take over root privileges on the device. The vulnerable…

  • CVE-2023-46753MedOct 26, 2023
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

  • CVE-2023-5521CriOct 11, 2023
    risk 0.00cvss 9.8epss 0.01

    Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

  • CVE-2023-5106HigOct 2, 2023
    risk 0.00cvss 8.2epss 0.01

    An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

  • CVE-2023-40168HigAug 17, 2023
    risk 0.00cvss 7.4epss 0.01

    TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a malicious project or custom extension to read arbitrary files from disk and upload them to a remote server. The only required user…

  • CVE-2023-34958MedJun 8, 2023
    risk 0.00cvss 4.3epss 0.00

    Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.

  • CVE-2023-1979MedMay 8, 2023
    risk 0.00cvss 4.9epss 0.00

    The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't…

  • CVE-2023-27486HigMar 8, 2023
    risk 0.00cvss 8.1epss 0.01

    xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are configured as a mechanism to secure clusters in XCAT, it is possible for a local root user from one node to obtain credentials to SSH to any node in any zone,…

  • CVE-2023-27485MedMar 7, 2023
    risk 0.00cvss 4.3epss 0.01

    thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to…

  • CVE-2021-32163CriFeb 17, 2023
    risk 0.00cvss 9.8epss 0.01

    Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

  • CVE-2021-4275MedDec 21, 2022
    risk 0.00cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is…