VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,238)

page 210 of 212
  • CVE-2023-46753MedOct 26, 2023
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

  • CVE-2023-5521CriOct 11, 2023
    risk 0.00cvss 9.8epss 0.01

    Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

  • CVE-2023-5106HigOct 2, 2023
    risk 0.00cvss 8.2epss 0.01

    An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

  • CVE-2023-40168HigAug 17, 2023
    risk 0.00cvss 7.4epss 0.01

    TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a malicious project or custom extension to read arbitrary files from disk and upload them to a remote server. The only required user…

  • CVE-2023-34958MedJun 8, 2023
    risk 0.00cvss 4.3epss 0.00

    Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.

  • CVE-2023-1979MedMay 8, 2023
    risk 0.00cvss 4.9epss 0.00

    The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't…

  • CVE-2023-27486HigMar 8, 2023
    risk 0.00cvss 8.1epss 0.01

    xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are configured as a mechanism to secure clusters in XCAT, it is possible for a local root user from one node to obtain credentials to SSH to any node in any zone,…

  • CVE-2023-27485MedMar 7, 2023
    risk 0.00cvss 4.3epss 0.01

    thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to…

  • CVE-2022-4397MedDec 10, 2022
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to…

  • CVE-2022-41970LowDec 1, 2022
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.…

  • CVE-2022-41944LowNov 28, 2022
    risk 0.00cvss 3.5epss 0.00

    Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the…

  • CVE-2022-39385MedNov 14, 2022
    risk 0.00cvss 6.5epss 0.01

    Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This…

  • CVE-2022-39302MedOct 14, 2022
    risk 0.00cvss 5.5epss 0.00

    Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and…

  • CVE-2022-39275MedOct 6, 2022
    risk 0.00cvss 5.3epss 0.01

    Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose…

  • CVE-2022-36074MedSep 15, 2022
    risk 0.00cvss 6.4epss 0.01

    Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that…

  • CVE-2022-31168MedJul 22, 2022
    risk 0.00cvss 5.4epss 0.01

    Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server…

  • CVE-2022-31087HigJun 27, 2022
    risk 0.00cvss 7.8epss 0.00

    LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An…

  • CVE-2022-31039MedJun 27, 2022
    risk 0.00cvss 4.3epss 0.01

    Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has…

  • CVE-2022-1706MedMay 17, 2022
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…

  • CVE-2022-24865MedApr 20, 2022
    risk 0.00cvss 6.5epss 0.01

    HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0,…