CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2022-26279 CRITICAL
EyouCMS v1.5.5 - Unauthenticated Direct Request in /data/sqldata
CVSS 9.8
CVE-2022-24385 MEDIUM
SmarterTrack 100.0.8019.14010 - Info Disclosure
CVSS 6.5
CVE-2022-26159 MEDIUM
Ametys CMS <4.5.0 - Info Disclosure
CVSS 5.3
CVE-2022-23607 MEDIUM
treq 21.1.0-22.1.0 - Exposure of Sensitive Information via Supercookies
CVSS 6.5
CVE-2021-40616 MEDIUM
thinkcmf <5.1.7 - Privilege Escalation
CVSS 6.5
CVE-2021-44582 HIGH
Sourcecodester Money Transfer Management System 1.0 - Privilege Escalation via Forced Browsing
CVSS 8.8
CVE-2021-34588 HIGH
Bender CC612 and ICC15xx Firmware 5.11.0-5.11.1 - Unauthenticated Sensitive Data Exposure via Backup Export
CVSS 8.6
CVE-2021-46378 HIGH
DLink DIR850 ET850-1.08TRb03 - Info Disclosure
CVSS 7.5
CVE-2021-24046 MEDIUM
Ray-Ban Stories <2107460.6810.0 - Info Disclosure
CVSS 5.3
CVE-2021-42748 MEDIUM
Beaver Builder <2.5.0.3 - Auth Bypass
CVSS 5.3
CVE-2021-24831 HIGH
Tab WordPress <1.3.2 - Info Disclosure
CVSS 7.5
CVE-2021-24695 HIGH
Simple Download Monitor <3.9.6 - Info Disclosure
CVSS 7.5
CVE-2021-42671 HIGH
Sourcecodester Engineers Online Portal - Auth Bypass
CVSS 7.5
CVE-2021-36560 CRITICAL
Phone Shop Sales Managements System <1.0 - Auth Bypass
CVSS 9.8
CVE-2021-36745 CRITICAL
Trend Micro ServerProtect - Auth Bypass
CVSS 9.8
CVE-2021-40875 HIGH
Gurock TestRail <7.2.0.3014 - Info Disclosure
CVSS 7.5
CVE-2021-26085 MEDIUM KEV
Atlassian Confluence Server <7.4.10, >7.5.0-7.12.2 - Info Disclosure
CVSS 5.3
CVE-2021-20114 HIGH
TCExam <= 14.8.1 - Unauthenticated Sensitive Information Exposure via Cache Backup Directory
CVSS 7.5
CVE-2021-28150 MEDIUM
Hongdian H8922 3.0.5 - Information Disclosure
CVSS 5.5
CVE-2021-24238 MEDIUM
Findeo and Realteo < 1.3.1 and < 1.2.4 - Authenticated Arbitrary Property Deletion via property_id Parameter
CVSS 6.5
CVE-2021-24215 CRITICAL
Controlled Admin Access < 1.5.2 - Unauthenticated Improper Access Control
CVSS 9.8
CVE-2021-30144 MEDIUM
GLPI Dashboard <1.0.2 - Auth Bypass
CVSS 4.3
CVE-2021-22180 MEDIUM
GitLab 13.4-13.6.7 - Unauthenticated Direct Request Access to Analytic Pages
CVSS 4.3
CVE-2021-3113 HIGH
Netsia SEBA+ <0.16.1 build 70-e669dcd7 - Info Disclosure
CVSS 7.5
CVE-2020-35570 MEDIUM
MymbCONNECT24 <2.11.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 235