CWE-425— Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.— MITRE CWE catalog
237 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-425page 3 of 5
- CVE-2021-40616MEDIUMCVSS 6.5EG 6.52022-06-14
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user manageme…
- CVE-2021-40875HIGHCVSS 7.5EG 8.02021-09-22
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of appli…
- CVE-2021-42671HIGHCVSS 7.5EG 7.52021-11-05
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all t…
- CVE-2021-42748MEDIUMCVSS 5.3EG 5.32022-01-10
In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API.
- CVE-2021-44582HIGHCVSS 8.8EG 8.82022-06-10
A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.
- CVE-2021-46378HIGHCVSS 7.5EG 7.62022-03-04
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.
- CVE-2022-1077HIGHCVSS 5.3EG 7.52022-03-29
A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware information. The att…
- CVE-2022-1551MEDIUMCVSS 6.5EG 6.52022-07-25
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
- CVE-2022-2192HIGHCVSS 7.5EG 8.82022-07-19
Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions late…
- CVE-2022-23607MEDIUMCVSS 6.5EG 6.52022-02-01
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound…
- CVE-2022-24385MEDIUMCVSS 6.5EG 6.52022-03-14
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
- CVE-2022-24932MEDIUMCVSS 4.2EG 4.62022-03-10
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
- CVE-2022-2544HIGHCVSS 7.5EG 7.52022-08-22
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.
- CVE-2022-2551HIGHCVSS 7.5EG 7.52022-08-22
The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing downloa…
- CVE-2022-25626MEDIUMCVSS 5.3EG 5.32022-12-16
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
- CVE-2022-26159MEDIUMCVSS 5.3EG 5.32022-02-28
The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain …
- CVE-2022-26279CRITICALCVSS 9.8EG 9.82022-03-24
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
- CVE-2022-26653MEDIUMCVSS 5.3EG 5.32022-04-16
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
- CVE-2022-26777MEDIUMCVSS 5.3EG 5.32022-04-16
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
- CVE-2022-27480HIGHCVSS 7.5EG 7.52022-04-12
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenti…
- CVE-2022-28365MEDIUMCVSS 5.3EG 5.32022-04-09
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network …
- CVE-2022-28799HIGHCVSS 8.8EG 8.82022-06-02
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached …
- CVE-2022-28991HIGHCVSS 7.5EG 7.52022-05-20
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
- CVE-2022-29238MEDIUMCVSS 4.3EG 4.32022-06-14
Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidde…
- CVE-2022-31480HIGHCVSS 7.5EG 7.52022-06-06
An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500…
- CVE-2022-31484HIGHCVSS 7.5EG 7.52022-06-06
An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 wh…
- CVE-2022-31485MEDIUMCVSS 5.3EG 5.32022-06-06
An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP25…
- CVE-2022-31847HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.
- CVE-2022-34570HIGHCVSS 7.5EG 7.52022-07-25
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
- CVE-2022-34571HIGHCVSS 8.0EG 8.02022-07-25
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml.
- CVE-2022-34572MEDIUMCVSS 5.7EG 5.72022-07-25
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.
- CVE-2022-34573MEDIUMCVSS 6.3EG 6.32022-07-25
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml.
- CVE-2022-34574MEDIUMCVSS 5.7EG 5.72022-07-25
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini.
- CVE-2022-36158HIGHCVSS 8.0EG 8.02022-09-26
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
- CVE-2022-4057MEDIUMCVSS 5.3EG 5.32023-01-02
The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.
- CVE-2022-40845MEDIUMCVSS 6.5EG 6.52022-11-15
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be …
- CVE-2022-41746CRITICALCVSS 9.1EG 9.12022-10-10
A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first ob…
- CVE-2022-42197MEDIUMCVSS 6.5EG 6.52022-10-20
In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.
- CVE-2022-42238HIGHCVSS 8.8EG 8.82022-10-11
A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
- CVE-2022-42438HIGHCVSS 7.5EG 8.82023-02-08
IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210.
- CVE-2022-42953HIGHCVSS 7.5EG 7.52022-12-25
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-51…
- CVE-2022-43110CRITICALCVSS 9.8EG 9.82025-08-22
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system in…
- CVE-2022-45276CRITICALCVSS 9.8EG 9.82022-11-23
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.
- CVE-2022-47700HIGHCVSS 7.5EG 7.52023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid …
- CVE-2023-1663MEDIUMCVSS 6.5EG 6.52023-03-29
Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache…
- CVE-2023-1682HIGHCVSS 4.3EG 7.52023-03-29
A vulnerability has been found in Xunrui CMS 4.61 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dayrui/My/Config/Install.txt. The manipulation leads to direct request. The attack can…
- CVE-2023-1699CRITICALCVSS 4.3EG 9.82023-03-30
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in versi…
- CVE-2023-22834LOWCVSS 2.7EG 2.72023-06-27
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permi…
- CVE-2023-2524MEDIUMCVSS 6.3EG 6.32023-05-04
A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/#/. The manipulation leads to direct request. It is possible to initiate the attack remotely. The associated i…
- CVE-2023-28160MEDIUMCVSS 6.5EG 6.52023-06-02
When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. This vulnerability affects Firefox < 111.
Map vulnerabilities like CWE-425 to your infrastructure
EchelonGraph correlates every CVE — across CWE-425 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →