CWE-425
AllowedDirect Request ('Forced Browsing')
Abstraction: Base · Status: Incomplete
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
297 vulnerabilities reference this CWE, most recent first.
GHSA-382V-J99G-HW2P
Vulnerability from github – Published: 2023-10-26 18:30 – Updated: 2023-10-26 18:30A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.
{
"affected": [],
"aliases": [
"CVE-2023-5786"
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-26T16:15:08Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.",
"id": "GHSA-382v-j99g-hw2p",
"modified": "2023-10-26T18:30:23Z",
"published": "2023-10-26T18:30:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5786"
},
{
"type": "WEB",
"url": "https://github.com/Qxyday/GeoServe---unauthorized"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243592"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243592"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-3GQJ-CMXR-P4X2
Vulnerability from github – Published: 2021-04-30 17:32 – Updated: 2024-11-18 22:24Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an httpoxy issue.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "Twisted"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "16.3.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2016-1000111"
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"github_reviewed": true,
"github_reviewed_at": "2021-04-23T20:33:04Z",
"nvd_published_at": "2020-03-11T20:15:00Z",
"severity": "MODERATE"
},
"details": "Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the `HTTP_PROXY` environment variable, which might allow remote attackers to redirect a CGI application\u0027s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an `httpoxy` issue.",
"id": "GHSA-3gqj-cmxr-p4x2",
"modified": "2024-11-18T22:24:19Z",
"published": "2021-04-30T17:32:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-1000111"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2020-214.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/twisted/twisted"
},
{
"type": "WEB",
"url": "https://twistedmatrix.com/pipermail/twisted-web/2016-August/005268.html"
},
{
"type": "WEB",
"url": "https://twistedmatrix.com/trac/ticket/8623"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2016/07/18/6"
},
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Forced Browsing in Twisted"
}
GHSA-3P6F-JVP3-W6PM
Vulnerability from github – Published: 2025-03-31 06:30 – Updated: 2025-03-31 06:30Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.
{
"affected": [],
"aliases": [
"CVE-2025-26689"
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-31T05:15:15Z",
"severity": "CRITICAL"
},
"details": "Direct request (\u0027Forced Browsing\u0027) issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.",
"id": "GHSA-3p6f-jvp3-w6pm",
"modified": "2025-03-31T06:30:27Z",
"published": "2025-03-31T06:30:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26689"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU91154745"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-084-04"
},
{
"type": "WEB",
"url": "https://www.inaba.co.jp/files/chocomini_vulnerability.pdf"
},
{
"type": "WEB",
"url": "https://www.nozominetworks.com/blog/unpatched-vulnerabilities-in-production-line-cameras-may-allow-remote-surveillance-hinder-stoppage-recording"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-3WFP-4XF2-2WR9
Vulnerability from github – Published: 2025-03-10 12:30 – Updated: 2025-03-10 12:30A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
{
"affected": [],
"aliases": [
"CVE-2025-2147"
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-10T11:15:38Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.",
"id": "GHSA-3wfp-4xf2-2wr9",
"modified": "2025-03-10T12:30:55Z",
"published": "2025-03-10T12:30:55Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2147"
},
{
"type": "WEB",
"url": "https://github.com/fubxx/CVE/blob/main/%E7%91%9E%E7%94%B0%E7%8E%B0%E4%BB%A3%E5%86%9C%E5%9C%BA%E6%95%B0%E5%AD%97%E5%8C%96%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.299058"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.299058"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.506593"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-3WG2-8VCR-5M74
Vulnerability from github – Published: 2023-01-03 00:30 – Updated: 2023-01-09 18:30The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.
{
"affected": [],
"aliases": [
"CVE-2022-4057"
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-01-02T22:15:00Z",
"severity": "MODERATE"
},
"details": "The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin\u0027s exported settings and logs.",
"id": "GHSA-3wg2-8vcr-5m74",
"modified": "2023-01-09T18:30:18Z",
"published": "2023-01-03T00:30:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4057"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/95ee1b9c-1971-4c35-8527-5764e9ed64af"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-43VG-7P43-J62W
Vulnerability from github – Published: 2026-10-03 00:31 – Updated: 2026-10-03 00:31Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
{
"affected": [],
"aliases": [
"CVE-2026-105046"
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-02T22:16:54Z",
"severity": "MODERATE"
},
"details": "Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.",
"id": "GHSA-43vg-7p43-j62w",
"modified": "2026-10-03T00:31:13Z",
"published": "2026-10-03T00:31:13Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-105046"
},
{
"type": "WEB",
"url": "https://devnet.kentico.com/download/hotfixes"
},
{
"type": "WEB",
"url": "https://www.kentico.com/platform"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-4446-W42R-XVJ9
Vulnerability from github – Published: 2023-07-06 19:24 – Updated: 2025-04-18 15:31An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
{
"affected": [],
"aliases": [
"CVE-2022-25626"
],
"database_specific": {
"cwe_ids": [
"CWE-287",
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-16T16:15:00Z",
"severity": "MODERATE"
},
"details": "An unauthenticated user can access Identity Manager\u2019s management console specific page URLs. However, the system doesn\u2019t allow the user to carry out server side tasks without a valid web session.",
"id": "GHSA-4446-w42r-xvj9",
"modified": "2025-04-18T15:31:29Z",
"published": "2023-07-06T19:24:05Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25626"
},
{
"type": "WEB",
"url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/21136"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-4487-MJX5-9V4R
Vulnerability from github – Published: 2022-10-11 19:00 – Updated: 2022-10-12 12:00A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
{
"affected": [],
"aliases": [
"CVE-2022-42238"
],
"database_specific": {
"cwe_ids": [
"CWE-269",
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-10-11T18:15:00Z",
"severity": "HIGH"
},
"details": "A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.",
"id": "GHSA-4487-mjx5-9v4r",
"modified": "2022-10-12T12:00:22Z",
"published": "2022-10-11T19:00:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42238"
},
{
"type": "WEB",
"url": "https://github.com/draco1725/localpriv/blob/main/poc"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-44G9-QRMG-2WVF
Vulnerability from github – Published: 2022-10-20 19:00 – Updated: 2022-10-21 19:01In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.
{
"affected": [],
"aliases": [
"CVE-2022-42197"
],
"database_specific": {
"cwe_ids": [
"CWE-269",
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-10-20T13:15:00Z",
"severity": "MODERATE"
},
"details": "In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.",
"id": "GHSA-44g9-qrmg-2wvf",
"modified": "2022-10-21T19:01:10Z",
"published": "2022-10-20T19:00:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42197"
},
{
"type": "WEB",
"url": "https://github.com/ciph0x01/Simple-Exam-Reviewer-Management-System-CVE/blob/main/CVE-2022-42197.md"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com/php/15160/simple-exam-reviewer-management-system-phpoop-free-source-code.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-45M2-RWC3-RQ9V
Vulnerability from github – Published: 2022-05-13 01:08 – Updated: 2022-05-13 01:08Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
{
"affected": [],
"aliases": [
"CVE-2019-9552"
],
"database_specific": {
"cwe_ids": [
"CWE-425"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-03-04T04:29:00Z",
"severity": "CRITICAL"
},
"details": "Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.",
"id": "GHSA-45m2-rwc3-rq9v",
"modified": "2022-05-13T01:08:19Z",
"published": "2022-05-13T01:08:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9552"
},
{
"type": "WEB",
"url": "https://github.com/lmy1342554547/p2pProject/issues/1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
Mitigation
Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files.
Mitigation
Consider using MVC based frameworks such as Struts.
CAPEC-127: Directory Indexing
An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method of triggering directory contents as output is to construct a request containing a path that terminates in a directory name rather than a file name since many applications are configured to provide a list of the directory's contents when such a request is received. An adversary can use this to explore the directory tree on a target as well as learn the names of files. This can often end up revealing test files, backup files, temporary files, hidden files, configuration files, user accounts, script contents, as well as naming conventions, all of which can be used by an attacker to mount additional attacks.
CAPEC-143: Detect Unpublicized Web Pages
An adversary searches a targeted web site for web pages that have not been publicized. In doing this, the adversary may be able to gain access to information that the targeted site did not intend to make public.
CAPEC-144: Detect Unpublicized Web Services
An adversary searches a targeted web site for web services that have not been publicized. This attack can be especially dangerous since unpublished but available services may not have adequate security controls placed upon them given that an administrator may believe they are unreachable.
CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB)
An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two devices communicating via Bluetooth. The adversary uses an Adversary in the Middle setup to modify packets sent between the two devices during the authentication process, specifically the entropy bits. Knowledge of the number of entropy bits will allow the attacker to easily decrypt information passing over the line of communication.
CAPEC-87: Forceful Browsing
An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front controller or similar design pattern is employed to protect access to portions of a web application. Forceful browsing enables an attacker to access information, perform privileged operations and otherwise reach sections of the web application that have been improperly protected.