CWE-862 授权机制缺失 类弱点 6896 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-862 属于缺失授权漏洞,指产品在用户访问资源或执行操作时未进行权限校验。攻击者通常通过直接修改请求参数或构造恶意 URL,绕过前端限制以访问未授权数据或执行敏感操作。开发者应避免仅依赖前端验证,需在服务端对每个请求实施严格的身份认证与权限检查,确保用户仅能访问其被授权的资源,从而从根本上消除越权风险。
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);
sub DisplayPrivateMessage { my($id) = @_; my $Message = LookupMessageObject($id); print "From: " . encodeHTML($Message->{from}) . "<br>\n"; print "Subject: " . encodeHTML($Message->{subject}) . "\n"; print "<hr>\n"; print "Body: " . encodeHTML($Message->{body}) . "\n"; } my $q = new CGI; # For purposes of this example, assume that CWE-309 and # CWE-523 do not apply. if (! AuthenticateUser($q->param('username'), $q->param('password'))) { ExitError("invalid username or password"); } my $id = $q->param('id'); DisplayPrivateMessage($id);
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-4379 | WordPress Plugin WooCommerce Multi Currency 安全漏洞 — CURCY - WooCommerce Multi Currency - Currency Switcher | 6.5 | Medium | 2023-06-07 |
| CVE-2021-4337 | WordPress Plugin Sixteen XforWooCommerce Add-On Plugins 安全漏洞 — Package Quantity Discount | 8.8 | High | 2023-06-07 |
| CVE-2021-4381 | WordPress Plugin uListing 安全漏洞 — Directory Listings WordPress plugin – uListing | 9.8 | Critical | 2023-06-07 |
| CVE-2022-4950 | WordPress多个Cool Plugins开发插件 安全漏洞 — The Events Calendar Events Notification Bar Addon | 8.8 | High | 2023-06-07 |
| CVE-2021-4383 | WordPress Plugin WP Quick FrontEnd Editor 安全漏洞 — WP Quick FrontEnd Editor – WordPress Plugin | 8.1 | High | 2023-06-07 |
| CVE-2020-36730 | WordPress Plugin CMP 安全漏洞 — CMP – Coming Soon & Maintenance Plugin by NiteoThemes | 8.3 | High | 2023-06-07 |
| CVE-2021-4376 | WordPress Plugin WooCommerce Multi Currency 安全漏洞 — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x | 4.3 | Medium | 2023-06-07 |
| CVE-2021-4375 | WordPress Plugin Welcart e-Commerce 安全漏洞 — Welcart e-Commerce | 4.3 | Medium | 2023-06-07 |
| CVE-2023-3126 | WordPress plugin B2BKing 安全漏洞 — B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More | 4.3 | Medium | 2023-06-07 |
| CVE-2020-36725 | WordPress Plugin TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins 安全漏洞 — TI WooCommerce Wishlist Pro | 8.8 | High | 2023-06-07 |
| CVE-2021-4374 | WordPress Plugin WordPress Automatic 安全漏洞 — WordPress Automatic Plugin | 9.1 | Critical | 2023-06-07 |
| CVE-2021-4370 | WordPress Plugin uListing 安全漏洞 — Directory Listings WordPress plugin – uListing | 9.8 | Critical | 2023-06-07 |
| CVE-2021-4371 | WordPress Plugin WP Quick FrontEnd Editor 安全漏洞 — WP Quick FrontEnd Editor – WordPress Plugin | 4.3 | Medium | 2023-06-07 |
| CVE-2021-4369 | WordPress Plugin Frontend File Manager 安全漏洞 — Frontend File Manager Plugin | 5.8 | Medium | 2023-06-07 |
| CVE-2023-3125 | WordPress plugin B2BKing 安全漏洞 — B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More | 6.5 | Medium | 2023-06-07 |
| CVE-2021-4368 | WordPress Plugin Frontend File Manager 安全漏洞 — Frontend File Manager Plugin | 9.9 | Critical | 2023-06-07 |
| CVE-2021-4366 | WordPress Plugin PWA for WP & AMP 安全漏洞 — PWA for WP – Progressive Web Apps Made Simple | 6.3 | Medium | 2023-06-07 |
| CVE-2020-36719 | WordPress Theme ListingPro - WordPress Directory & Listing 安全漏洞 — ListingPro - WordPress Directory & Listing Theme | 9.8 | Critical | 2023-06-07 |
| CVE-2020-36720 | WordPress Plugin Kali Forms 安全漏洞 — Kali Forms — Contact Form & Drag-and-Drop Builder | 7.1 | High | 2023-06-07 |
| CVE-2020-36716 | WordPress Plugin WP Activity Log 安全漏洞 — WP Activity Log | 7.3 | High | 2023-06-07 |
| CVE-2020-36715 | WordPress Plugin Login/Signup Popup 安全漏洞 — Login & Register Customizer – Popup | Slider | Inline | WooCommerce | 7.4 | High | 2023-06-07 |
| CVE-2020-36712 | WordPress Plugin Kali Forms 安全漏洞 — Kali Forms — Contact Form & Drag-and-Drop Builder | 8.6 | High | 2023-06-07 |
| CVE-2019-25143 | WordPress Plugin GDPR Cookie Compliance 安全漏洞 — GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law | 5.4 | Medium | 2023-06-07 |
| CVE-2019-25142 | WordPress theme Mesmerize & Materialis 安全漏洞 — Materialis | 8.8 | High | 2023-06-07 |
| CVE-2021-4359 | WordPress Plugin Frontend File Manager 安全漏洞 — Frontend File Manager Plugin | 6.5 | Medium | 2023-06-07 |
| CVE-2019-25141 | WordPress Plugin Easy WP SMTP 安全漏洞 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more | 9.8 | Critical | 2023-06-07 |
| CVE-2021-4356 | WordPress Plugin Frontend File Manager 安全漏洞 — Frontend File Manager Plugin | 9.0 | Critical | 2023-06-07 |
| CVE-2022-4948 | WordPress Plugin FlyingPress 安全漏洞 — FlyingPress | 4.3 | Medium | 2023-06-07 |
| CVE-2021-4357 | WordPress Plugin uListing 安全漏洞 — Directory Listings WordPress plugin – uListing | 9.1 | Critical | 2023-06-07 |
| CVE-2021-4355 | WordPress Plugin Welcart e-Commerce 安全漏洞 — Welcart e-Commerce | 7.5 | High | 2023-06-07 |
CWE-862(授权机制缺失) 是常见的弱点类别,本平台收录该类弱点关联的 6896 条 CVE 漏洞。