CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

Parent: CWE-863 - Incorrect Authorization

The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

115 vulnerabilities with CWE-942
CVE-2025-25234 HIGH
Omnissa Unified Access Gateway < 2503 - CORS Bypass
CVSS 7.1
CVE-2025-30354 MEDIUM
Bruno < 1.39.1 - Unauthenticated Remote Code Execution via Malicious Collection Import
CVSS 4.3
CVE-2025-2865 MEDIUM
SaTECH BCU Firmware 2.1.3 - Stored Cross-Site Scripting via Untrusted Domain Resources
CVSS 6.1
CVE-2025-1083 LOW
Mindskip xzs-mysql 3.9.0 - Permissive Cross-domain Security Policy with Untrusted Domains in CORS Handler
CVSS 3.1
CVE-2024-23578 MEDIUM
Hclsoftware Aftermarket Epc - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 4.2
CVE-2024-11071 HIGH
Cyberdigm DestinyECM - Cross-Site Request Forgery via JSON Hijacking
CVSS 8.8
CVE-2024-22348 MEDIUM
IBM DevOps Velocity 5.0.0, IBM UrbanCode Velocity 4.0.0-4.0.25 - SSRF
CVSS 5.3
CVE-2024-53276 MEDIUM
home-gallery <= 1.15.0 - Permissive Cross-domain Security Policy in CORS Middleware
CVE-2024-49763 HIGH
PlexRipper < 0.24.0 - Unauthenticated Sensitive Information Exposure via CORS Misconfiguration
CVE-2024-45642 MEDIUM
IBM Security ReaQta 3.12-3.12.11 - Stored Cross-Site Scripting in Web UI
CVSS 5.3
CVE-2024-10315 MEDIUM
Gliffy Online <4.14.0-6 - Info Disclosure
CVE-2024-6449 MEDIUM
HyperView Geoportal Toolkit <8.5.0 - SSRF
CVSS 6.5
CVE-2024-41657 HIGH
Casdoor <= 1.577.0 - Authenticated Cross-Origin Request Forgery via Origin Header Prefix Check
CVSS 8.1
CVE-2024-41659 HIGH
memos < 0.21.0 - Unauthenticated CORS Misconfiguration with Credentials
CVSS 8.1
CVE-2024-32862 MEDIUM
ExacqVision Web Service < 24.03 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 6.8
CVE-2024-37131 HIGH
Dell Policy Manager for Secure Connect Gateway 5.18.00.20-5.24.00.14 - Unauthenticated CORS Bypass
CVSS 7.5
CVE-2024-23823 MEDIUM
vantage6 < 4.2.1 and >=0 < 4.3.0 - Permissive Cross-domain Security Policy
CVSS 4.2
CVE-2024-25124 CRITICAL
Fiber < 2.52.1 - Insecure CORS Configuration with Wildcard Origin and Credentials
CVSS 9.4
CVE-2024-21382 MEDIUM
Microsoft Edge Chromium < 121.0.2277.83 - Information Disclosure via Permissive Cross-domain Security Policy
CVSS 4.3
CVE-2023-37401 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.13.1 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.3
CVE-2023-37526 MEDIUM
HCL DRYiCE Lucy - Cross-Origin Resource Sharing Misconfiguration
CVSS 6.5
CVE-2023-38125 HIGH
Softing edgeAggregator < 3.50 - Authenticated Remote Code Execution via Missing Content Security Policy Headers
CVSS 8.8
CVE-2023-38122 HIGH
Inductive Automation Ignition < 8.1.26 - Authenticated RCE via OPC UA Quick Client
CVSS 7.2
CVE-2023-45213 MEDIUM
Westermo L206-f2g Firmware - Permissive CORS Policy
CVSS 6.6
CVE-2023-50940 MEDIUM
IBM PowerSC 1.3, 2.0, 2.1 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.3
Details
Vulnerabilities 115