CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2024-33373 MEDIUM
Lb-link Bl-w1210m Firmware - IDOR
CVSS 6.3
CVE-2024-2472 CRITICAL
LatePoint Plugin <4.9.9 - Info Disclosure
CVSS 9.1
CVE-2024-29181 LOW
Strapi <4.19.1 - Info Disclosure
CVSS 2.3
CVE-2024-5438 MEDIUM
Themeum Tutor Lms < 2.7.2 - IDOR
CVSS 4.3
CVE-2024-5131 MEDIUM
lunary-ai/lunary <1.2.2 - Info Disclosure
CVSS 6.5
CVE-2024-5130 HIGH
lunary-ai/lunary <1.2.8 - Auth Bypass
CVSS 7.5
CVE-2024-5128 HIGH
lunary-ai/lunary <1.2.2 - Info Disclosure
CVSS 8.8
CVE-2024-36399 HIGH
Kanboard - Privilege Escalation
CVSS 8.2
CVE-2024-4886 MEDIUM
Buddyboss Platform < 2.6.00 - IDOR
CVSS 4.3
CVE-2024-4750 MEDIUM
Buddyboss < 2.6.0 - IDOR
CVSS 5.3
CVE-2024-4274 MEDIUM
WordPress Essential Real Estate <4.4.2 - Info Disclosure
CVSS 4.3
CVE-2024-32045 MEDIUM
Mattermost <9.5.4, <9.6.2, <8.1.13 - Privilege Escalation
CVSS 5.9
CVE-2024-5258 MEDIUM
Gitlab < 16.10.6 - Incorrect Authorization
CVSS 4.4
CVE-2024-5166 MEDIUM
Google Cloud's Looker - Info Disclosure
CVSS 6.5
CVE-2024-4154 MEDIUM
Lunary < 1.2.26 - IDOR
CVSS 6.5
CVE-2024-4151 HIGH
Lunary < 1.2.25 - IDOR
CVSS 8.1
CVE-2024-4843 MEDIUM
ePO - Privilege Escalation
CVSS 4.3
CVE-2024-4279 MEDIUM
Tutor LMS - Insecure Direct Object Reference
CVSS 6.5
CVE-2024-4819 MEDIUM
Campcodes Online Laundry Management System - Improper Authorization
CVSS 4.3
CVE-2024-4817 MEDIUM
Campcodes Online Laundry Management System 1.0 - Info Disclosure
CVSS 6.3
CVE-2024-33818 HIGH
Globitel KSA SpeechLog v8.1 - Info Disclosure
CVSS 7.5
CVE-2024-1693 MEDIUM
SP Project & Document Manager - Info Disclosure
CVSS 4.3
CVE-2024-4538 HIGH
Janto Ticketing Software <4.3r10 - Info Disclosure
CVSS 7.5
CVE-2024-4537 HIGH
Janto Ticketing Software <4.3r10 - Info Disclosure
CVSS 7.5
CVE-2024-34383 MEDIUM
SEOPress <7.7.1 - Auth Bypass
CVSS 5.3
Details
Vulnerabilities 1,575
Exploit Likelihood High