Skip to main content

Threats Tagged 'cwe-602'

View all threats tagged with 'cwe-602'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-602

Threats Tagged 'cwe-602'

Click on any threat for detailed analysis and mitigation recommendations

TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables share_map. The client hides the map, but the public JSON response still includes the itinerary and place names, coordinates, addresses, descriptions, notes, and prices. Anyone holding the valid share token can therefore read location and route information that the owner explicitly chose not to share, although the random token remains required and the flaw does not permit modification. This issue is fixed in version 3.3.0.

Join the discussion

A vulnerability in the J2Store extension for Joomla allows unauthenticated attackers to mark any order as Failed. This affects versions 1.0.0 through 3.3.22, 4.0.0 through 4.0.22, and 4.1.0 through 4.1.7. The flaw enables denial-of-service against the order pipeline by mass-failing pending orders or flipping fulfilled orders back to Failed, causing operational disruption and increased support load.

Join the discussion

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available.

Join the discussion

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.

Join the discussion

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made its verification request with `CURLOPT_SSL_VERIFYPEER` disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when `mc_gross` was a positive number; omitting the field from the POST body (`floatval(null) == 0`) skipped the check entirely. Combined with a merchant-configured `receiver_email` and a sequential, enumerable order id read from the `custom` field, an anonymous POST was enough to move a pending order straight to `CONFIRMED` with no payment, or force another customer's pending order to `FAILED`. `paypalv2.php` performed no amount check under any circumstances.

Join the discussion

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.

Join the discussion

A vulnerability in the clusterclaims-controller component of Red Hat multicluster engine for Kubernetes 2.1 allows tenants with standard permissions on ClusterClaim resources to delete any ManagedCluster by manipulating the spec.namespace field. This occurs due to a missing ownership check, enabling unauthorized deletion of critical clusters including the hub's local-cluster or other tenants' clusters, leading to denial of service.

Join the discussion

A vulnerability in the Convert Forms extension for Joomla (versions 1.0.0 through 5.2.5) allows unauthenticated visitors to bypass access control on the front-end Submissions view, enabling them to list form submissions. This is due to client-side enforcement of security that should be handled server-side.

Join the discussion

MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though the frontend hides registration controls when the flag is false. An unauthenticated remote attacker can call the endpoint directly and create a valid account on an instance whose administrator disabled public registration. The process_auth_header function in webserver/handlers/base.py also does not verify the account's active flag, so the newly created and unactivated account can authenticate immediately and access user-level API functionality. The bypass defeats the intended account-creation policy and can supply the low-privilege account required by related authorization vulnerabilities. This issue is fixed in version 3.42.0.

Join the discussion

CVE-2026-67363 is a high-severity vulnerability in the Balbooa Forms extension for Joomla versions 1.0.0 through 2.4.3.1. It allows unauthenticated attackers to tamper with payment amounts by exploiting the stripeCharges and payAuthorize endpoints, which accept client-controlled charge totals without verification. This flaw enables attackers to purchase items at arbitrary prices, including very low amounts, and to forge line items, quantities, and shipping details. The endpoints lack authentication and CSRF protections, increasing the risk of exploitation.

Join the discussion

Showing 1 to 10 of 65 results

Filters:Tag: cwe-602
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses