VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,734)

page 5 of 187
  • CVE-2024-42966CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

  • CVE-2024-6202CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and…

  • CVE-2024-6695CriJul 31, 2024
    risk 0.64cvss 9.8epss 0.01

    it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

  • CVE-2024-4447CriJul 26, 2024
    risk 0.64cvss 9.9epss 0.00

    In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this is information that would and should be available to admins who possess "Sign In As" powers,…

  • CVE-2024-36536CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2023-38389CriJun 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

  • CVE-2024-36265CriJun 12, 2024
    risk 0.64cvss 9.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST requests. As this project is retired, we…

  • CVE-2024-31682CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

  • CVE-2024-35353CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization.

  • CVE-2024-21010CriApr 16, 2024
    risk 0.64cvss 9.9epss 0.01

    Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access…

  • CVE-2024-28394CriMar 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.

  • CVE-2023-6036CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.02

    The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any…

  • CVE-2023-24052CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.

  • CVE-2023-24051CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.

  • CVE-2023-43119CriOct 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.

  • CVE-2023-40309CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could…

  • CVE-2023-32748CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

  • CVE-2023-36092CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.02

    Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-36091CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-36090CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.