CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2023-45596 MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Info Disclosure
CVSS 5.3
CVE-2023-46186 MEDIUM
IBM Jazz for Service Management <1.1.3.20 - Info Disclosure
CVSS 5.3
CVE-2023-50935 MEDIUM
IBM PowerSC 1.3, 2.0, and 2.1 - Unauthenticated Direct Request Access
CVSS 6.5
CVE-2023-44320 MEDIUM
RUGGEDCOM RM1224 LTE(4G) EU, RUGGEDCOM RM1224 LTE(4G) NAM, SCALANCE...
CVSS 4.3
CVE-2023-5786 MEDIUM
GeoServer GeoWebCache <1.15.1 - Direct Request
CVSS 5.3
CVE-2023-5702 MEDIUM
Viessmann Vitogate 300 <2.1.3.0 - Direct Request
CVSS 4.3
CVE-2023-45809 LOW
Wagtail < 4.1.9 - Authenticated Information Disclosure via User Account Bulk Action URL
CVSS 2.7
CVE-2023-4018 MEDIUM
GitLab <16.2.5-16.3.1 - Info Disclosure
CVSS 4.3
CVE-2023-4544 MEDIUM
Byzoro Smart S85F Management Platform <20230809 - Direct Request
CVSS 4.3
CVE-2023-3426 MEDIUM
Liferay Portal 7.4.3.81-7.4.3.85 and DXP 7.4 update 81-85 - Authenticated Missing Authorization in Organization Selector
CVSS 4.3
CVE-2023-3792 MEDIUM
Beijing Netcon NS-ASG 6.3 - Direct Request
CVSS 4.3
CVE-2023-22834 LOW
Contour < 9.642.0 - Missing Authorization for Analysis Creation
CVSS 2.7
CVE-2023-28160 MEDIUM
Firefox < 111.0 - Information Disclosure via Web Extension File Redirect
CVSS 6.5
CVE-2023-2524 MEDIUM
Control iD RHiD 23.3.19.0 - Open Redirect
CVSS 6.3
CVE-2023-1699 MEDIUM
Rapid7 Nexpose <6.6.187 - Forced Browsing
CVSS 4.3
CVE-2023-1663 MEDIUM
Coverity <2023.3.2 - Info Disclosure
CVSS 6.5
CVE-2023-1682 MEDIUM
Xunrui CMS 4.61 - Direct Request Exposure via Install.txt
CVSS 4.3
CVE-2022-43110 CRITICAL
Voltronic Power ViewPower <1.04-21353 & PowerShield Netguard <1.04-...
CVSS 9.8
CVE-2022-42438 HIGH
IBM Cloud Pak for Multicloud Management Monitoring <2.4 - Info Disc...
CVSS 7.5
CVE-2022-47700 HIGH
COMFAST CF-WR623N <V2.3.0.1 - Auth Bypass
CVSS 7.5
CVE-2022-4057 MEDIUM
Autoptimize <3.1.0 - Info Disclosure
CVSS 5.3
CVE-2022-42953 HIGH
ZKTeco ZEM and ZMM Firmware - Unauthenticated Sensitive Information Exposure via Direct Request
CVSS 7.5
CVE-2022-25626 MEDIUM
Symantec Identity Governance and Administration - Unauthenticated Forced Browsing
CVSS 5.3
CVE-2022-45276 CRITICAL
YJCMS 1.0.9 - Unauthenticated Administrator Password Exposure via User Edit Endpoint
CVSS 9.8
CVE-2022-40845 MEDIUM
Tenda AC1200 Router W15Ev2 V15.11.0.10(1576) - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 235