VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 82 of 187
  • CVE-2024-6512MedSep 25, 2024
    risk 0.42cvss 6.5epss 0.00

    Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.

  • CVE-2024-8601MedSep 9, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to…

  • CVE-2024-45509MedSep 1, 2024
    risk 0.42cvss 6.5epss 0.00

    In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

  • CVE-2024-42490HigAug 22, 2024
    risk 0.42cvss 7.5epss 0.00

    authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs//view_certificate/,…

  • CVE-2024-20466MedAug 21, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege…

  • CVE-2024-6337MedAug 20, 2024
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitable via user access token and…

  • CVE-2024-41670HigJul 26, 2024
    risk 0.42cvss 7.5epss 0.00

    In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment…

  • CVE-2024-5817MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corresponding project board. This…

  • CVE-2024-2231MedJul 3, 2024
    risk 0.42cvss 6.5epss 0.00

    The allows any authenticated user to join a private group due to a missing authorization check on a function

  • CVE-2024-5071MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

  • CVE-2024-1639MedJun 21, 2024
    risk 0.42cvss 6.5epss 0.00

    The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for…

  • CVE-2024-4390MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.01

    The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any…

  • CVE-2024-2098HigJun 13, 2024
    risk 0.42cvss 7.5epss 0.00

    The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download…

  • CVE-2022-45168MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate…

  • CVE-2024-23669MedJun 5, 2024
    risk 0.42cvss 6.5epss 0.01

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

  • CVE-2024-36377MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

  • CVE-2024-36376MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

  • CVE-2024-36364MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

  • CVE-2024-34434MedMay 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.

  • CVE-2024-31409MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.00

    Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.