CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2024-2346 MEDIUM
Ninjateam Filebird < 5.6.4 - IDOR
CVSS 5.4
CVE-2024-24312 HIGH
Vaales Technologies V_QRS <2024-01-17 - Info Disclosure
CVSS 7.5
CVE-2024-33383 HIGH
Xxyopen Novel-plus < 4.3.0 - IDOR
CVSS 7.5
CVE-2024-28320 HIGH
Mayurik Hospital Management System - IDOR
CVSS 7.6
CVE-2024-33542 MEDIUM
Crelly Slider < 1.4.6 - IDOR
CVSS 4.3
CVE-2024-4294 MEDIUM
PHPGurukul Doctor Appointment Management System 1.0 - Improper Cont...
CVSS 6.3
CVE-2024-33668 CRITICAL
Zammad < 6.3.0 - IDOR
CVSS 9.1
CVE-2024-32823 MEDIUM
Blazzdev Rate MY Post < 3.4.5 - IDOR
CVSS 5.3
CVE-2024-32808 MEDIUM
Metagauss Profilegrid < 5.8.0 - IDOR
CVSS 5.4
CVE-2024-32772 MEDIUM
Metagauss Profilegrid < 5.8.0 - IDOR
CVSS 4.3
CVE-2024-32166 HIGH
Webid v1.2.1 - Horizontal Privilege Escalation
CVSS 8.8
CVE-2024-32683 MEDIUM
Wpmet WP Ultimate Review < 2.3.0 - IDOR
CVSS 5.3
CVE-2024-32604 MEDIUM
Plechev Andrey WP-Recall <16.26.5 - Auth Bypass
CVSS 4.3
CVE-2024-1626 HIGH
Lunary < 1.0.0 - IDOR
CVSS 8.1
CVE-2024-22439 MEDIUM
HPE FlexFabric/FlexNetwork - Privilege Escalation
CVSS 6.9
CVE-2024-1625 MEDIUM
Lunary - IDOR
CVSS 6.5
CVE-2024-2543 MEDIUM
Permalink Manager Lite < 2.4.3.2 - Missing Authorization
CVSS 4.3
CVE-2024-2261 MEDIUM
WordPress <5.8.2 - Info Disclosure
CVSS 4.3
CVE-2024-1289 MEDIUM
LearnPress - WordPress LMS Plugin <4.2.6.3 - Info Disclosure
CVSS 6.5
CVE-2024-0872 MEDIUM
Watu Quiz <3.4.1 - Info Disclosure
CVSS 4.3
CVE-2024-27630 HIGH
GNU Savane <3.12 - Info Disclosure
CVSS 7.5
CVE-2024-31815 CRITICAL
TOTOLINK EX200 V4.0.3c.7314_B20191204 - Info Disclosure
CVSS 9.1
CVE-2024-31296 MEDIUM
Reputeinfosystems Bookingpress < 1.0.82 - IDOR
CVSS 4.3
CVE-2024-31291 MEDIUM
Metagauss Profilegrid < 5.7.7 - IDOR
CVSS 4.3
CVE-2024-3139 MEDIUM
Oretnom23 Computer Laboratory Management System - Improper Authorization
CVSS 5.4
Details
Vulnerabilities 1,575
Exploit Likelihood High