VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,734)

page 183 of 187
  • CVE-2021-4268MedDec 21, 2022
    risk 0.00cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this…

  • CVE-2022-4397MedDec 10, 2022
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to…

  • CVE-2022-41970LowDec 1, 2022
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.…

  • CVE-2022-41944LowNov 28, 2022
    risk 0.00cvss 3.5epss 0.00

    Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the…

  • CVE-2022-39385MedNov 14, 2022
    risk 0.00cvss 6.5epss 0.01

    Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This…

  • CVE-2022-39302MedOct 14, 2022
    risk 0.00cvss 5.5epss 0.00

    Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and…

  • CVE-2022-39275MedOct 6, 2022
    risk 0.00cvss 5.3epss 0.01

    Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose…

  • CVE-2022-36074MedSep 15, 2022
    risk 0.00cvss 6.4epss 0.01

    Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that…

  • CVE-2022-31168MedJul 22, 2022
    risk 0.00cvss 5.4epss 0.01

    Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server…

  • CVE-2022-31087HigJun 27, 2022
    risk 0.00cvss 7.8epss 0.00

    LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An…

  • CVE-2022-31039MedJun 27, 2022
    risk 0.00cvss 4.3epss 0.01

    Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has…

  • CVE-2022-1706MedMay 17, 2022
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…

  • CVE-2022-24865MedApr 20, 2022
    risk 0.00cvss 6.5epss 0.01

    HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0,…

  • CVE-2022-24841MedApr 18, 2022
    risk 0.00cvss 6.5epss 0.01

    fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…

  • CVE-2022-1224MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-1223MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-0406MedApr 3, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.

  • CVE-2022-1177MedMar 30, 2022
    risk 0.00cvss 4.3epss 0.01

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.

  • CVE-2022-24755HigMar 15, 2022
    risk 0.00cvss 8.1epss 0.02

    Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired…

  • CVE-2022-24128HigMar 13, 2022
    risk 0.00cvss 8.0epss 0.01

    Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer…