VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 7 of 209
  • CVE-2023-36994CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.01

    In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.

  • CVE-2023-29381CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.

  • CVE-2022-46080CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.03

    Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

  • CVE-2021-46891CriJul 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2021-46890CriJul 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2023-27716CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running on it.

  • CVE-2023-28698CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by modifying URL parameters to gain administrator privileges to perform arbitrary system operation or disrupt service.

  • CVE-2023-27388CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products…

  • CVE-2023-30771CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version…

  • CVE-2023-23594CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated users, such as file uploads and…

  • CVE-2023-26829CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full authentication bypass.

  • CVE-2023-1136CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.

  • CVE-2023-28611CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.

  • CVE-2023-23064CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.

  • CVE-2022-47002CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.06

    A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

  • CVE-2022-45172CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web…

  • CVE-2022-23739CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app installed on an organization to gain access to and modify most…

  • CVE-2022-44039CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with…

  • CVE-2022-31692CriOct 31, 2022
    risk 0.64cvss 9.8epss 0.04

    Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring…

  • CVE-2022-37767CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input…