CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2023-6504 MEDIUM
User Profile Builder <3.10.7 - Info Disclosure
CVSS 4.3
CVE-2023-6506 MEDIUM
WP 2FA - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-6223 MEDIUM
LearnPress <4.2.5.7 - Info Disclosure
CVSS 4.3
CVE-2023-6630 MEDIUM
Contact Form 7 - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-48783 MEDIUM
PortiPortal <7.2.1-<6.0.14-<5.3.8 - Auth Bypass
CVSS 5.4
CVE-2023-49251 HIGH
SIMATIC CN 4100 < V2.7 - Privilege Escalation
CVSS 8.8
CVE-2023-51502 HIGH
WooCommerce Stripe Payment Gateway <7.6.1 - Auth Bypass
CVSS 7.5
CVE-2023-50342 HIGH
Hcltech Dryice Myxalytics - IDOR
CVSS 7.1
CVE-2023-45893 HIGH
Floorsight Customer Portal Q3 2023 - Info Disclosure
CVSS 7.5
CVE-2023-45892 HIGH
Floorsight Insights Q3 2023 - Info Disclosure
CVSS 7.5
CVE-2023-51503 MEDIUM
WooPayments <6.9.2 - Auth Bypass
CVSS 5.9
CVE-2023-50267 MEDIUM
Metersphere < 2.10.10 - Improper Privilege Management
CVSS 4.3
CVE-2023-46646 MEDIUM
GitHub Enterprise Server <3.17.19-3.11.0 - Info Disclosure
CVSS 5.3
CVE-2023-49765 MEDIUM
Blazzdev Rate MY Post < 3.4.2 - IDOR
CVSS 4.3
CVE-2023-47191 MEDIUM
Kainelabs Youzify < 1.2.3 - IDOR
CVSS 6.5
CVE-2023-32799 MEDIUM
Woocommerce Shipping Multiple Addresses < 3.8.3 - IDOR
CVSS 6.5
CVE-2023-32747 MEDIUM
Automattic Woocommerce Bookings < 1.15.78 - IDOR
CVSS 5.4
CVE-2023-35916 HIGH
WooPayments <5.9.0 - Auth Bypass
CVSS 7.5
CVE-2023-35914 HIGH
WooCommerce Woo Subscriptions <5.1.2 - Auth Bypass
CVSS 7.5
CVE-2023-36520 MEDIUM
MarketingFire Editorial Calendar <3.7.12 - Auth Bypass
CVSS 5.4
CVE-2023-35876 HIGH
Automattic Woocommerce Square < 3.8.2 - IDOR
CVSS 8.1
CVE-2023-46311 LOW
wpDiscuz <7.6.3 - Auth Bypass
CVSS 2.7
CVE-2023-41796 MEDIUM
Sunshinephotocart Sunshine Photo Cart < 3.0 - IDOR
CVSS 5.3
CVE-2023-38513 MEDIUM
Jordy Meow Photo Engine <6.2.5 - Auth Bypass
CVSS 5.4
CVE-2023-37871 HIGH
Automattic Woocommerce Gocardless < 2.5.7 - IDOR
CVSS 8.2
Details
Vulnerabilities 1,575
Exploit Likelihood High