Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-11-01 CVE-2021-24742 Incorrect Authorization vulnerability in Radiustheme Logo Slider and Showcase
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
network
low complexity
radiustheme CWE-863
6.5
2021-11-01 CVE-2021-24757 Incorrect Authorization vulnerability in Stylishpricelist Stylish Price List
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.
network
low complexity
stylishpricelist CWE-863
5.3
2021-10-29 CVE-2021-41189 Incorrect Authorization vulnerability in Duraspace Dspace 7.0
DSpace is an open source turnkey repository application.
network
low complexity
duraspace CWE-863
7.2
2021-10-21 CVE-2021-39321 Incorrect Authorization vulnerability in Heateor Sassy Social Share 3.3.23
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file.
network
low complexity
heateor CWE-863
8.8
2021-10-14 CVE-2021-38345 Incorrect Authorization vulnerability in Brizy Brizy-Page Builder
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor.
network
low complexity
brizy CWE-863
6.5
2021-10-13 CVE-2021-20803 Incorrect Authorization vulnerability in Cybozu Remote Service Manager 3.1.8/3.1.9
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.
network
low complexity
cybozu CWE-863
5.4
2021-10-11 CVE-2021-42137 Incorrect Authorization vulnerability in Zammad
An issue was discovered in Zammad before 5.0.1.
network
low complexity
zammad CWE-863
5.3
2021-10-07 CVE-2021-28661 Incorrect Authorization vulnerability in Silverstripe
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
network
low complexity
silverstripe CWE-863
4.3
2021-10-05 CVE-2021-22262 Incorrect Authorization vulnerability in Gitlab
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page
network
low complexity
gitlab CWE-863
4.3
2021-10-04 CVE-2021-41093 Incorrect Authorization vulnerability in Wire
Wire is an open source secure messenger.
network
low complexity
wire CWE-863
critical
9.8