BaseIncomplete
CWE-425Direct Request ('Forced Browsing')
Category: other
Description
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Common consequences· 1
- Confidentiality / Integrity / Availability / Access Control — Read Application Data, Modify Application Data, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity
Potential mitigations· 2
- [Architecture and Design, Operation]Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files.
- [Architecture and Design]Consider using MVC based frameworks such as Struts.
Related CAPEC attack patterns· 5
References
Exploits (incoming)5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Detect Unpublicized Web Pagescapec-143 | 100% | live |
| AttackPattern | Key Negotiation of Bluetooth Attack (KNOB)capec-668 | 100% | live |
| AttackPattern | Directory Indexingcapec-127 | 100% | live |
| AttackPattern | Detect Unpublicized Web Servicescapec-144 | 100% | live |
| AttackPattern | Forceful Browsingcapec-87 | 100% | live |
(incoming)12
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-26689cve-2025-26689 | 0% | live |
| Vulnerability | CVE-2025-32367cve-2025-32367 | 0% | live |
| Vulnerability | CVE-2025-46690cve-2025-46690 | 0% | live |
| Vulnerability | CVE-2025-48201cve-2025-48201 | 0% | live |
| Vulnerability | CVE-2025-48205cve-2025-48205 | 0% | live |
| Vulnerability | CVE-2025-48207cve-2025-48207 | 0% | live |
| Vulnerability | CVE-2025-52024cve-2025-52024 | 0% | live |
| Vulnerability | CVE-2025-6352cve-2025-6352 | 0% | live |
| Vulnerability | CVE-2026-22732cve-2026-22732 | 0% | live |
| Vulnerability | CVE-2026-32867cve-2026-32867 | 0% | live |
| KEVEntry | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerabilitykev-cve-2021-26085 | 0% | live |
| KEVEntry | Apache OFBiz Forced Browsing Vulnerabilitykev-cve-2024-45195 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.