VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,257)

page 96 of 213
  • CVE-2024-6337MedAug 20, 2024
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitable via user access token and…

  • CVE-2024-41670HigJul 26, 2024
    risk 0.42cvss 7.5epss 0.00

    In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment…

  • CVE-2024-5817MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corresponding project board. This…

  • CVE-2024-2231MedJul 3, 2024
    risk 0.42cvss 6.5epss 0.00

    The allows any authenticated user to join a private group due to a missing authorization check on a function

  • CVE-2024-5071MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

  • CVE-2024-1639MedJun 21, 2024
    risk 0.42cvss 6.5epss 0.00

    The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for…

  • CVE-2024-4390MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.01

    The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any…

  • CVE-2024-2098HigJun 13, 2024
    risk 0.42cvss 7.5epss 0.00

    The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download…

  • CVE-2022-45168MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate…

  • CVE-2024-23669MedJun 5, 2024
    risk 0.42cvss 6.5epss 0.01

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

  • CVE-2024-36377MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

  • CVE-2024-36376MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

  • CVE-2024-36364MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

  • CVE-2024-34434MedMay 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.

  • CVE-2024-31409MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.00

    Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.

  • CVE-2024-3957MedMay 2, 2024
    risk 0.42cvss 6.5epss 0.01

    The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are…

  • CVE-2024-34146MedMay 2, 2024
    risk 0.42cvss 6.5epss 0.01

    Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.

  • CVE-2024-1307MedApr 15, 2024
    risk 0.42cvss 6.5epss 0.01

    The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions

  • CVE-2024-31134MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

  • CVE-2023-50811MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and…