VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 83 of 187
  • CVE-2024-3957MedMay 2, 2024
    risk 0.42cvss 6.5epss 0.01

    The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are…

  • CVE-2024-34146MedMay 2, 2024
    risk 0.42cvss 6.5epss 0.01

    Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.

  • CVE-2024-1307MedApr 15, 2024
    risk 0.42cvss 6.5epss 0.01

    The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions

  • CVE-2024-31134MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

  • CVE-2023-50811MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and…

  • CVE-2024-28098MedMar 12, 2024
    risk 0.42cvss 6.4epss 0.02

    The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super user role. This…

  • CVE-2024-28229MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

  • CVE-2024-23833HigFeb 12, 2024
    risk 0.42cvss 7.5epss 0.01

    OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the host filesystem. Due to the newer MySQL driver…

  • CVE-2023-6564MedFeb 8, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role…

  • CVE-2023-35836MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PSK, during device setup and reconfiguration. Upon success, the attacker is able to further…

  • CVE-2024-23675MedJan 22, 2024
    risk 0.42cvss 6.5epss 0.00

    In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.

  • CVE-2024-21736MedJan 9, 2024
    risk 0.42cvss 6.4epss 0.00

    SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of…

  • CVE-2023-47827MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Events Addon for Elementor: from n/a through 2.1.3.

  • CVE-2023-29484MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.00

    In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.

  • CVE-2023-5195MedSep 29, 2023
    risk 0.42cvss 6.5epss 0.00

    Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

  • CVE-2023-39965MedAug 10, 2023
    risk 0.42cvss 6.5epss 0.00

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target…

  • CVE-2023-24471MedAug 9, 2023
    risk 0.42cvss 6.5epss 0.00

    An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality. An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining…

  • CVE-2023-38209MedAug 9, 2023
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability that could lead to a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access other…

  • CVE-2023-20800MedAug 7, 2023
    risk 0.42cvss 6.5epss 0.00

    In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420955.

  • CVE-2023-28468MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.