CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2023-2958 CRITICAL
Orjinyazilim Ats Pro < 20230714 - IDOR
CVSS 9.8
CVE-2023-3700 MEDIUM
Easyappointments < 1.5.0 - IDOR
CVSS 6.3
CVE-2023-2190 MEDIUM
GitLab CE/EE <15.11.10-16.0.6-16.1.1 - Info Disclosure
CVSS 6.5
CVE-2023-3105 HIGH
LearnDash LMS <4.6.0 - Info Disclosure
CVSS 8.8
CVE-2023-30960 MEDIUM
Foundry Job-Tracker <4.645.0 - Info Disclosure
CVSS 4.3
CVE-2023-30956 MEDIUM
Foundry Comments <2.267.0 - Info Disclosure
CVSS 5.3
CVE-2023-3219 MEDIUM
Eventon < 2.1.2 - IDOR
CVSS 5.3
CVE-2023-37242 CRITICAL
Huawei Emui - IDOR
CVSS 9.8
CVE-2023-3063 HIGH
SP Project & Document Manager <4.67 - Insecure Direct Object Reference
CVSS 8.8
CVE-2023-32352 MEDIUM
Apple Ipados < 16.5 - IDOR
CVSS 5.5
CVE-2023-23679 MEDIUM
Jshelpdesk < 2.7.7 - IDOR
CVSS 4.6
CVE-2023-26428 MEDIUM
Open-Xchange AppSuite Backend - Information Disclosure via Snippet ID
CVSS 6.5
CVE-2023-21131 HIGH
Google Android - IDOR
CVSS 7.8
CVE-2023-34000 HIGH
WooCommerce Stripe Payment Gateway <7.4.0 - Info Disclosure
CVSS 7.5
CVE-2023-3048 CRITICAL
TMT Lockcell <15 - Auth Bypass
CVSS 9.8
CVE-2023-1889 MEDIUM
Directorist <7.5.4 - Info Disclosure
CVSS 6.5
CVE-2023-0694 MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 6.5
CVE-2023-0693 MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 6.5
CVE-2023-0692 MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 4.3
CVE-2023-0691 MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 4.3
CVE-2023-0688 MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 6.5
CVE-2023-0985 HIGH
Mbconnectline Mbconnect24 < 2.13.3 - IDOR
CVSS 8.8
CVE-2023-33956 MEDIUM
Kanboard <1.2.30 - IDOR
CVSS 4.3
CVE-2023-3066 HIGH
Mobatime mobile app <1.3.20 - Auth Bypass
CVSS 8.1
CVE-2023-32310 HIGH
Dataease < 1.18.7 - IDOR
CVSS 8.1
Details
Vulnerabilities 1,575
Exploit Likelihood High