VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 21 of 187
  • CVE-2024-4146CriJun 8, 2024
    risk 0.57cvss 9.8epss 0.01

    In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to. Specifically, the vulnerability is located in the `checkProjectAccess`…

  • CVE-2024-25421CriMar 26, 2024
    risk 0.57cvss 9.8epss 0.02

    An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

  • CVE-2024-2915HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.

  • CVE-2023-49982HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.

  • CVE-2024-25108CriFeb 12, 2024
    risk 0.57cvss 9.9epss 0.01

    Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the…

  • CVE-2024-23653CriJan 31, 2024
    risk 0.57cvss 9.8epss 0.03

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use…

  • CVE-2020-10676HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

  • CVE-2023-36646HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

  • CVE-2023-48859HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.

  • CVE-2023-43961HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2021-4334HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with…

  • CVE-2023-38218HigOct 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and privilege escalation.

  • CVE-2023-36556HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.

  • CVE-2023-4997HigOct 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.

  • CVE-2023-33237HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only…

  • CVE-2022-26563HigJul 18, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.

  • CVE-2023-2759HigJul 17, 2023
    risk 0.57cvss 8.8epss 0.01

    A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using this vulnerability.

  • CVE-2023-33190CriJun 29, 2023
    risk 0.57cvss 9.9epss 0.01

    Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access control (RBAC) permissions resulted in an attacker being able to obtain cluster control…

  • CVE-2023-25729HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files…

  • CVE-2022-46308HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.01

    SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information.