CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2024-31095 MEDIUM
Ricard Torres Thumbs Rating <5.1.0 - Auth Bypass
CVSS 5.3
CVE-2024-30543 MEDIUM
UPQODE Whizz <1.1.18 - Auth Bypass
CVSS 6.5
CVE-2024-30513 MEDIUM
Metagauss Profilegrid < 5.7.3 - IDOR
CVSS 6.5
CVE-2024-30507 LOW
Molongui <4.7.7 - Auth Bypass
CVSS 2.7
CVE-2024-29024 MEDIUM
Fit2cloud Jumpserver < 3.10.6 - IDOR
CVSS 4.6
CVE-2024-29020 MEDIUM
Fit2cloud Jumpserver < 3.10.6 - IDOR
CVSS 4.6
CVE-2024-1313 MEDIUM
Grafana < 9.5.18 - IDOR
CVSS 6.5
CVE-2024-29194 HIGH
OneUptime - Info Disclosure
CVSS 8.3
CVE-2024-2538 MEDIUM
Permalink Manager Lite < 2.4.3.2 - Missing Authorization
CVSS 5.4
CVE-2024-1604 MEDIUM
BMC Control-m < 9.0.20.238 - IDOR
CVSS 6.4
CVE-2024-2577 HIGH
Oretnom23 Employee Task Management System - IDOR
CVSS 7.3
CVE-2024-2576 HIGH
Oretnom23 Employee Task Management System - IDOR
CVSS 7.3
CVE-2024-2575 HIGH
Oretnom23 Employee Task Management System - IDOR
CVSS 7.3
CVE-2024-2574 HIGH
Oretnom23 Employee Task Management System - IDOR
CVSS 7.3
CVE-2024-1640 MEDIUM
Contact Form Builder Plugin <2.10.1 - Info Disclosure
CVSS 5.3
CVE-2024-0839 MEDIUM
FeedWordPress <2022.0222 - Info Disclosure
CVSS 5.3
CVE-2024-23112 HIGH
Fortinet Fortiproxy < 7.0.14 - IDOR
CVSS 8.0
CVE-2024-27302 CRITICAL
go-zero <1.4.4 - SSRF
CVSS 9.1
CVE-2024-1470 HIGH
Netiq Client Login Extension - IDOR
CVSS 7.1
CVE-2024-25983 LOW
Moodle < 4.1.9 - IDOR
CVSS 3.5
CVE-2024-22455 MEDIUM
Dell Mobility - E-Lab Navigator <3.2.0 - Auth Bypass
CVSS 4.4
CVE-2024-0421 MEDIUM
Mappresspro Mappress Maps For Wordpress < 2.88.16 - IDOR
CVSS 5.3
CVE-2024-1075 LOW
Webfactoryltd Minimal Coming Soon & M... - Information Disclosure
CVSS 3.7
CVE-2024-0366 MEDIUM
Squirrly Starbox < 3.4.7 - IDOR
CVSS 4.3
CVE-2024-22305 HIGH
Kali Forms <2.3.36 - Auth Bypass
CVSS 7.5
Details
Vulnerabilities 1,575
Exploit Likelihood High