CWE-862 授权机制缺失 类弱点 5967 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-862 属于缺失授权漏洞,指产品在用户访问资源或执行操作时未进行权限校验。攻击者通常通过直接修改请求参数或构造恶意 URL,绕过前端限制以访问未授权数据或执行敏感操作。开发者应避免仅依赖前端验证,需在服务端对每个请求实施严格的身份认证与权限检查,确保用户仅能访问其被授权的资源,从而从根本上消除越权风险。
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);sub DisplayPrivateMessage { my($id) = @_; my $Message = LookupMessageObject($id); print "From: " . encodeHTML($Message->{from}) . "<br>\n"; print "Subject: " . encodeHTML($Message->{subject}) . "\n"; print "<hr>\n"; print "Body: " . encodeHTML($Message->{body}) . "\n"; } my $q = new CGI; # For purposes of this example, assume that CWE-309 and # CWE-523 do not apply. if (! AuthenticateUser($q->param('username'), $q->param('password'))) { ExitError("invalid username or password"); } my $id = $q->param('id'); DisplayPrivateMessage($id);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-13520 | WordPress plugin Gift Cards 安全漏洞 — Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) | 5.3 | Medium | 2025-02-20 |
| CVE-2024-37363 | Hitachi Vantara Pentaho Business Analytics Server 安全漏洞 — Pentaho Data Integration & Analytics | 6.5 | Medium | 2025-02-19 |
| CVE-2024-13364 | WordPress plugin Raptive Ads 安全漏洞 — Raptive Ads | 5.3 | Medium | 2025-02-19 |
| CVE-2024-13231 | WordPress plugin WordPress Portfolio Builder 安全漏洞 — WordPress Portfolio Builder – Portfolio Gallery | 5.3 | Medium | 2025-02-19 |
| CVE-2024-13468 | WordPress plugin Trash Duplicate and 301 Redirect 安全漏洞 — Trash Duplicate and 301 Redirect | 7.5 | High | 2025-02-19 |
| CVE-2024-13719 | WordPress plugin PeproDev Ultimate Invoice 安全漏洞 — PeproDev Ultimate Invoice | 5.3 | Medium | 2025-02-19 |
| CVE-2025-22657 | WordPress plugin Atarim 安全漏洞 — Atarim | 7.5 | High | 2025-02-18 |
| CVE-2025-27013 | WordPress plugin MediCenter 安全漏洞 — MediCenter - Health Medical Clinic | 5.3 | Medium | 2025-02-18 |
| CVE-2024-13783 | WordPress plugin FormCraft 安全漏洞 — FormCraft | 4.3 | Medium | 2025-02-18 |
| CVE-2024-13316 | WordPress plugin Scratch & Win 安全漏洞 — Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more | 5.3 | Medium | 2025-02-18 |
| CVE-2024-13556 | WordPress plugin Affiliate Links 安全漏洞 — Affiliate Links – Link Cloaking and Management | 8.1 | High | 2025-02-18 |
| CVE-2024-13677 | WordPress plugin GetBookingsWP 安全漏洞 — GetBookingsWP – Appointments Booking Calendar Plugin For WordPress | 8.8 | High | 2025-02-18 |
| CVE-2024-13687 | WordPress plugin Team Builder 安全漏洞 — Team Builder – Meet the Team | 4.3 | Medium | 2025-02-18 |
| CVE-2025-26773 | WordPress plugin Analytify 安全漏洞 — Analytify | 4.3 | Medium | 2025-02-17 |
| CVE-2025-26765 | WordPress plugin Distance Based Shipping Calculator 安全漏洞 — Distance Based Shipping Calculator | 5.4 | Medium | 2025-02-16 |
| CVE-2025-22289 | WordPress plugin LTL Freight Quotes – Unishippers Edition 安全漏洞 — LTL Freight Quotes – Unishippers Edition | 6.5 | Medium | 2025-02-16 |
| CVE-2025-22291 | WordPress plugin LTL Freight Quotes – Worldwide Express Edition 安全漏洞 — LTL Freight Quotes – Worldwide Express Edition | 5.3 | Medium | 2025-02-16 |
| CVE-2024-13439 | WordPress plugin Team – Team Members Showcase Plugin 安全漏洞 — Team – Team Members Showcase Plugin | 4.3 | Medium | 2025-02-15 |
| CVE-2024-13752 | WordPress plugin WP Project Manager 安全漏洞 — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker | 6.5 | Medium | 2025-02-15 |
| CVE-2025-0935 | WordPress plugin Media Library Folders 安全漏洞 — Media Library Folders | 4.3 | Medium | 2025-02-15 |
| CVE-2024-13513 | WordPress plugin Oliver POS – A WooCommerce Point of Sale 安全漏洞 — Oliver POS – A WooCommerce Point of Sale (POS) | 9.8 | Critical | 2025-02-15 |
| CVE-2025-22702 | WordPress plugin Photography 安全漏洞 — Photography | 6.3 | Medium | 2025-02-14 |
| CVE-2025-22698 | WordPress plugin Accessibility Suite by Online ADA 安全漏洞 — Accessibility Suite | 6.3 | Medium | 2025-02-14 |
| CVE-2024-52500 | WordPress plugin Monetag Official Plugin 安全漏洞 — Monetag Official Plugin | 7.2 | High | 2025-02-14 |
| CVE-2025-24692 | WordPress plugin Bulk Menu Edit 安全漏洞 — Bulk Menu Edit | 7.1 | High | 2025-02-14 |
| CVE-2025-24607 | WordPress plugin IdeaPush 安全漏洞 — IdeaPush | 5.8 | Medium | 2025-02-14 |
| CVE-2025-23766 | WordPress plugin OPSI Israel Domestic Shipments 安全漏洞 — OPSI Israel Domestic Shipments | 6.5 | Medium | 2025-02-14 |
| CVE-2025-23771 | WordPress plugin Push Notification for Post and BuddyPress 安全漏洞 — Push Notification for Post and BuddyPress | 6.5 | Medium | 2025-02-14 |
| CVE-2025-23534 | WordPress plugin WPLingo 安全漏洞 — WPLingo | 6.5 | Medium | 2025-02-14 |
| CVE-2024-13639 | WordPress plugin Read More & Accordion 安全漏洞 — Read More & Accordion | 4.3 | Medium | 2025-02-13 |
CWE-862(授权机制缺失) 是常见的弱点类别,本平台收录该类弱点关联的 5967 条 CVE 漏洞。