VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 55 of 187
  • CVE-2022-39030HigSep 28, 2022
    risk 0.49cvss 7.5epss 0.01

    smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, who is not explicitly authorized to access the information, can access sensitive information.

  • CVE-2022-39958HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily…

  • CVE-2022-35487HigAug 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abused by an unauthenticated attacker to gain access to attachments, such as emails or attached files.

  • CVE-2022-1746HigJun 24, 2022
    risk 0.49cvss 7.6epss 0.00

    The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive…

  • CVE-2022-1589HigMay 30, 2022
    risk 0.49cvss 7.5epss 0.01

    The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

  • CVE-2022-27134HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.02

    EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.

  • CVE-2022-27055HigApr 19, 2022
    risk 0.49cvss 7.5epss 0.02

    ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including the database record password. NOTE: the…

  • CVE-2021-28505HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.

  • CVE-2022-0920HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data

  • CVE-2021-28504HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

  • CVE-2020-24771HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.

  • CVE-2022-25335HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulation, as exploited in the wild in February 2022. NOTE: although 2022-02-17 is the vendor's vulnerability announcement date, the vulnerability will not be…

  • CVE-2021-36749MedSep 24, 2021
    risk 0.49cvss 6.5epss 0.81

    In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server…

  • CVE-2021-40639HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

  • CVE-2020-19765HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack.

  • CVE-2020-12733HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.

  • CVE-2021-35197HigJul 2, 2021
    risk 0.49cvss 7.5epss 0.02

    In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block"…

  • CVE-2021-22119HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.06

    Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A…

  • CVE-2021-26845HigJun 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to…

  • CVE-2021-29628HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system call. This weakness could be combined…