Vulnerabilities > Direct Request ('Forced Browsing')

DATE CVE VULNERABILITY TITLE RISK
2021-09-22 CVE-2021-40875 Forced Browsing vulnerability in Gurock Testrail
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.
network
low complexity
gurock CWE-425
7.5
2021-08-03 CVE-2021-26085 Forced Browsing vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.
network
low complexity
atlassian CWE-425
5.3
2021-07-30 CVE-2021-20114 Forced Browsing vulnerability in Tecnick Tcexam
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
network
low complexity
tecnick CWE-425
7.5
2021-05-06 CVE-2021-28150 Forced Browsing vulnerability in Hongdian H8922 Firmware 3.0.5
Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi.
local
low complexity
hongdian CWE-425
5.5
2021-04-22 CVE-2021-24238 Forced Browsing vulnerability in Purethemes Findeo and Realteo
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter.
network
low complexity
purethemes CWE-425
6.5
2021-04-12 CVE-2021-24215 Forced Browsing vulnerability in Wpruby Controlled Admin Access
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2.
network
low complexity
wpruby CWE-425
critical
9.8
2021-04-06 CVE-2021-30144 Forced Browsing vulnerability in Glpi-Project Dashboard
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category.
network
low complexity
glpi-project CWE-425
4.3
2021-03-26 CVE-2021-22180 Forced Browsing vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 13.4.
network
low complexity
gitlab CWE-425
4.3
2021-02-16 CVE-2020-35570 Forced Browsing vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2.
network
low complexity
mbconnectline helmholz CWE-425
5.3
2021-01-17 CVE-2021-3113 Forced Browsing vulnerability in Netsia Seba+ 0.16.1
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request.
network
low complexity
netsia CWE-425
7.5