Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-862 (授权机制缺失) — Vulnerability Class 6896

6896 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CWE-862 represents a critical access control weakness where software fails to verify an actor’s permissions before granting access to resources or executing actions. Attackers typically exploit this flaw by manipulating requests to access sensitive data or perform privileged operations that should be restricted to authorized users. Without proper checks, malicious actors can bypass authentication mechanisms entirely, leading to unauthorized data exposure, modification, or system compromise. Developers mitigate this risk by implementing robust authorization logic at every entry point, ensuring that identity verification is coupled with strict permission validation. This involves checking user roles and access rights against the requested resource before processing any request. By integrating these checks into the application’s core architecture and utilizing established frameworks, teams can prevent unauthorized access and maintain the integrity of their systems against exploitation.

MITRE CWE Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Common Consequences (4)
Confidentiality Read Application Data, Read Files or Directories
An attacker could read sensitive data, either by reading the data directly from a data store that is not restricted, or by accessing insufficiently-protected, privileged functionality to read the data.
Integrity Modify Application Data, Modify Files or Directories
An attacker could modify sensitive data, either by writing the data directly to a data store that is not restricted, or by accessing insufficiently-protected, privileged functionality to write the data.
Access Control Gain Privileges or Assume Identity, Bypass Protection Mechanism
An attacker could gain privileges by modifying or reading critical data directly, or by accessing privileged functionality.
Availability DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other)
An attacker could gain unauthorized access to resources on the system and excessively consume those resources, leading to a denial of service.
Mitigations (5)
Architecture and Design Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the …
Architecture and Design Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible…
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
Architecture and Design For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page. One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests …
System Configuration, Installation Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.
Examples (2)
This function runs an arbitrary SQL query on a given database, returning the result of the query.
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);
Bad · PHP
The following program could be part of a bulletin board system that allows users to send private messages to each other. This program intends to authenticate the user before deciding whether a private message should be displayed. Assume that LookupMessageObject() ensures that the $id argument is numeric, constructs a filename based on that id, and reads the message details from that file. Also ass…
sub DisplayPrivateMessage { my($id) = @_; my $Message = LookupMessageObject($id); print "From: " . encodeHTML($Message->{from}) . "<br>\n"; print "Subject: " . encodeHTML($Message->{subject}) . "\n"; print "<hr>\n"; print "Body: " . encodeHTML($Message->{body}) . "\n"; } my $q = new CGI; # For purposes of this example, assume that CWE-309 and # CWE-523 do not apply. if (! AuthenticateUser($q->param('username'), $q->param('password'))) { ExitError("invalid username or password"); } my $id = $q->param('id'); DisplayPrivateMessage($id);
Bad · Perl
CVE ID Title CVSS Severity Published
CVE-2024-5648 LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update — LearnDash LMS – Reports 5.4 Medium 2024-07-09
CVE-2024-5856 Comment Images Reloaded <= 2.2.1 - Authenticated (Subscriber+) Arbitrary Media Deletion — Comment Images Reloaded 4.3 Medium 2024-07-09
CVE-2024-5600 Happy SCSS Compiler - Compile SCSS to CSS automatically <= 1.3.10 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue 5.4 Medium 2024-07-09
CVE-2024-3608 Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — PickPlugins Product Designer for WooCommerce 5.3 Medium 2024-07-09
CVE-2024-5704 XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update — Happy WooCommerce FAQs – Ultimate Product FAQ Plugin 4.3 Medium 2024-07-09
CVE-2024-6167 Just Custom Fields <= 3.3.2 - Missing Authorization via AJAX actions — Just Custom Fields 4.3 Medium 2024-07-09
CVE-2024-5993 Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Authorized (Subscriber+) Chatbot Settings Update — Cliengo – Chatbot 5.4 Medium 2024-07-09
CVE-2024-6180 EventON <= 2.2.15 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates — EventON – Events Calendar 7.2 High 2024-07-09
CVE-2024-39596 [CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now — SAP Enable Now 4.3 Medium 2024-07-09
CVE-2024-37172 [CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management) — SAP S/4HANA Finance (Advanced Payment Management) 5.4 Medium 2024-07-09
CVE-2024-37175 [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI) — SAP CRM WebClient UI 4.3 Medium 2024-07-09
CVE-2024-39592 [CVE-2024-39592] Missing Authorization check in SAP PDCE — SAP PDCE 7.7 High 2024-07-09
CVE-2024-5855 Media Hygiene <= 3.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion — Media Hygiene: Remove or Delete Unused Images and More! 4.3 Medium 2024-07-09
CVE-2024-37542 WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability — Responsive Image Gallery, Gallery Album 5.4 Medium 2024-07-06
CVE-2024-37903 Mastodon has improper authorship check on audience extension for existing posts — mastodon 8.2 High 2024-07-05
CVE-2024-5641 One Click Order Re-Order <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — One Click Order Re-Order 6.4 Medium 2024-07-04
CVE-2024-36113 Discourse missing authorization checks for suspending admins/moderators — discourse 4.9 Medium 2024-07-03
CVE-2024-6088 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 5.3 Medium 2024-07-02
CVE-2024-6012 Cost Calculator Builder <= 3.2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation — Cost Calculator Builder 4.3 Medium 2024-07-02
CVE-2024-5545 Motors – Car Dealer, Classifieds & Listing <= 1.4.9 - Missing Authorization — Motors – Car Dealership & Classified Listings Plugin 5.3 Medium 2024-07-02
CVE-2024-36995 Low-privileged user could create experimental items — Splunk Enterprise 4.3 Medium 2024-07-01
CVE-2024-5864 Easy Affiliate Links <= 3.7.3 - Missing Authorization to Authenticated (Subscriber+) Settings Reset — Easy Affiliate Links 4.3 Medium 2024-06-28
CVE-2024-5863 Easy Image Collage <= 1.13.5 - Missing Authorization to Authenticated (Contributor+) Data Clearance — Easy Image Collage 5.4 Medium 2024-06-28
CVE-2024-6071 PTC Creo Elements/Direct License Server Missing Authorization — Creo Elements/Direct License 10.0 Critical 2024-06-27
CVE-2024-2882 Missing Authorization in SDG Technologies PnPSCADA — PnPSCADA 9.8AI Critical AI 2024-06-27
CVE-2024-5710 Improper Access Control in Team Management in berriai/litellm — berriai/litellm 9.1AI Critical AI 2024-06-27
CVE-2024-5820 Unprotected WebSocket in stitionai/devika — stitionai/devika 9.8AI Critical AI 2024-06-27
CVE-2024-3115 Exposure of Sensitive Information to an Unauthorized Actor in GitLab — GitLab 4.3 Medium 2024-06-26
CVE-2024-6303 Missing Authorization in Conduit — Conduit 9.9 Critical 2024-06-25
CVE-2024-3249 Zita Elementor Site Library <= 1.6.2 - Missing Authorization to Page Creation and Options Modification — Zita Site Library for Elementor 4.3 Medium 2024-06-25

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 6896 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.