Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2023-47171MEDIUMAn information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev masterEPSS 1.1%CVE-2023-49862MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2023-49864MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2023-49863MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2026-11527HIGHConfig::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandleEPSS 1.1%CVE-2023-47862CRITICALA local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A speciEPSS 1.1%CVE-2023-21800HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2025-29819MEDIUMWindows Admin Center in Azure Portal Information Disclosure VulnerabilityEPSS 1.1%CVE-2026-30940HIGHbaserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCEEPSS 1.0%CVE-2020-2504MEDIUMAbsolute path traversal vulnerability in QESEPSS 1.0%CVE-2026-6101HIGHAMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font UploadEPSS 1.0%CVE-2024-41183HIGHTrend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevatioEPSS 1.0%CVE-2025-6691HIGHSureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionEPSS 1.0%CVE-2026-4132HIGHHTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' ParametersEPSS 1.0%CVE-2026-48749CRITICALIncus has an arbitrary file read+write on host via rootfs/ symlink in malicious imageEPSS 1.0%CVE-2024-4818MEDIUMCampcodes Online Laundry Management System index.php file inclusionEPSS 1.0%CVE-2023-4749MEDIUMSourceCodester Inventory Management System index.php file inclusionEPSS 1.0%CVE-2024-12875MEDIUMEasy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File DownloadEPSS 1.0%CVE-2026-54629HIGHAnyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeEPSS 1.0%CVE-2022-43513HIGHA vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 EPSS 1.0%