CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,800 vulnerabilities with CWE-639
CVE-2024-9554 LOW
Sovell Smart Canteen System <3.0.7303.30513 - Auth Bypass
CVSS 3.7
CVE-2024-47316 MEDIUM
Salon Booking System <10.9 - Auth Bypass
CVSS 4.3
CVE-2024-47657 MEDIUM
Shilpi Net Back Office - Info Disclosure
CVSS 6.5
CVE-2024-20513 MEDIUM
Cisco Meraki MX and Z Series - Unauthenticated Denial of Service via AnyConnect VPN Session Handler Brute Force
CVSS 5.8
CVE-2024-9298 MEDIUM
SourceCodester Online Railway Reservation System 1.0 - Improper Access Control in Ticket Handler
CVSS 4.3
CVE-2024-39319 MEDIUM
Aimeos Frontend Controller < 2020.10.15 - Insecure Direct Object Reference
CVSS 5.3
CVE-2024-8290 HIGH
WCFM - Frontend Manager <6.7.12 - Insecure Direct Object Reference
CVSS 8.8
CVE-2024-8485 CRITICAL
WordPress <4.7.1 - Privilege Escalation
CVSS 9.8
CVE-2024-8791 CRITICAL
Charitable < 1.8.1.14 - Unauthenticated Privilege Escalation via update_core_user() ID Parameter
CVSS 9.8
CVE-2024-45806 MEDIUM
Envoy < 1.28.7 - Authorization Bypass via RFC1918 Internal Address Trust
CVSS 6.5
CVE-2024-45614 MEDIUM
Puma < 5.6.9 - Authorization Bypass via Underscore Header Clobbering
CVSS 5.4
CVE-2024-46982 HIGH
Next.js 13.5.1-13.5.6 and 14.2.1-14.2.9 - Cache Poisoning via Crafted HTTP Request
CVSS 7.5
CVE-2024-45606 HIGH
Sentry 23.4.0-24.9.0 - Authenticated Authorization Bypass via Alert Rule Mute
CVSS 7.1
CVE-2024-45605 MEDIUM
Sentry 23.9.0-24.9.0 - Authenticated Authorization Bypass via User Alert Notification Deletion
CVSS 6.5
CVE-2024-47047 HIGH
powermail < 7.5.0 and 7.5.0-7.5.1 - Unauthenticated Insecure Direct Object Reference via Mail Parameter
CVSS 7.5
CVE-2024-6685 LOW
GitLab CE/EE <17.1.7-17.3.2 - Info Disclosure
CVSS 3.1
CVE-2024-46937 HIGH
MFASOFT Secure Authentication Server 1.8.0-1.9.040924 - Unauthenticated Authorization Bypass via Token Brute-Force
CVSS 7.5
CVE-2024-6087 MEDIUM
lunary < 1.4.9 - Unauthenticated Account Takeover via Invite Token Reuse
CVSS 6.5
CVE-2024-25270 MEDIUM
Mirapolis LMS 4.6.XX - Info Disclosure
CVSS 4.3
CVE-2024-3306 HIGH
SoliClub <4.4.0-5.2.1 - Auth Bypass
CVSS 7.5
CVE-2024-3305 HIGH
SoliClub <4.4.0-5.2.1 - Auth Bypass
CVSS 7.5
CVE-2024-27113 CRITICAL
SO Planning <1.52.02 - Unauthenticated Database Export Access Control Bypass
CVSS 9.8
CVE-2024-45786 MEDIUM
Reedos aiM-Star 2.0.1 - Authenticated Authorization Bypass via API Parameter Manipulation
CVSS 6.5
CVE-2024-45032 CRITICAL
Industrial Edge Management Pro/Virtual <V1.9.5-V2.3.1-1 - Auth Bypass
CVSS 10.0
CVE-2024-8601 MEDIUM
TechExcel Back Office Software <1.0.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 1,800
Exploit Likelihood High