CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

226 vulnerabilities with CWE-425
CVE-2023-3426 MEDIUM
Liferay Portal 7.4.3.81-7.4.3.85 and DXP 7.4 update 81-85 - Authenticated Missing Authorization in Organization Selector
CVSS 4.3
CVE-2023-3792 MEDIUM
Beijing Netcon NS-ASG 6.3 - Direct Request
CVSS 4.3
CVE-2023-22834 LOW
Contour < 9.642.0 - Missing Authorization for Analysis Creation
CVSS 2.7
CVE-2023-28160 MEDIUM
Firefox < 111.0 - Information Disclosure via Web Extension File Redirect
CVSS 6.5
CVE-2023-2524 MEDIUM
Control iD RHiD 23.3.19.0 - Open Redirect
CVSS 6.3
CVE-2023-1699 MEDIUM
Rapid7 Nexpose <6.6.187 - Forced Browsing
CVSS 4.3
CVE-2023-1663 MEDIUM
Coverity <2023.3.2 - Info Disclosure
CVSS 6.5
CVE-2023-1682 MEDIUM
Xunrui CMS 4.61 - Direct Request Exposure via Install.txt
CVSS 4.3
CVE-2022-43110 CRITICAL
Voltronic Power ViewPower <1.04-21353 & PowerShield Netguard <1.04-...
CVSS 9.8
CVE-2022-42438 HIGH
IBM Cloud Pak for Multicloud Management Monitoring <2.4 - Info Disc...
CVSS 7.5
CVE-2022-47700 HIGH
COMFAST CF-WR623N <V2.3.0.1 - Auth Bypass
CVSS 7.5
CVE-2022-4057 MEDIUM
Autoptimize <3.1.0 - Info Disclosure
CVSS 5.3
CVE-2022-42953 HIGH
ZKTeco ZEM and ZMM Firmware - Unauthenticated Sensitive Information Exposure via Direct Request
CVSS 7.5
CVE-2022-25626 MEDIUM
Symantec Identity Governance and Administration - Unauthenticated Forced Browsing
CVSS 5.3
CVE-2022-45276 CRITICAL
YJCMS 1.0.9 - Unauthenticated Administrator Password Exposure via User Edit Endpoint
CVSS 9.8
CVE-2022-40845 MEDIUM
Tenda AC1200 Router W15Ev2 V15.11.0.10(1576) - Info Disclosure
CVSS 6.5
CVE-2022-42197 MEDIUM
Simple Exam Reviewer Management System <1.0 - Privilege Escalation
CVSS 6.5
CVE-2022-42238 HIGH
Merchandise Online Store 1.0 - Vertical Privilege Escalation via Direct Request
CVSS 8.8
CVE-2022-41746 CRITICAL
Trend Micro Apex One - Privilege Escalation
CVSS 9.1
CVE-2022-36158 HIGH
Contec FXA3200 <1.13.00 - Command Injection
CVSS 8.0
CVE-2022-2551 HIGH
Duplicator <1.4.7 - Info Disclosure
CVSS 7.5
CVE-2022-2544 HIGH
Ninja Job Board <1.3.3 - Path Traversal
CVSS 7.5
CVE-2022-34574 MEDIUM
Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 - Info Disclo...
CVSS 5.7
CVE-2022-34573 MEDIUM
Wavlink WiFi-Repeater - Info Disclosure
CVSS 6.3
CVE-2022-34572 MEDIUM
Wavlink WiFi-Repeater - Info Disclosure
CVSS 5.7
Details
Vulnerabilities 226