CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2023-2978 MEDIUM
Abstrium Pydio Cells < 4.2.1 - IDOR
CVSS 4.6
CVE-2023-2883 HIGH
CBOT Chatbot <4.0.3.4-4.0.3.7 - Auth Bypass
CVSS 8.8
CVE-2023-2065 HIGH
Armoli Cargo Tracking System < 3558f28 - IDOR
CVSS 8.8
CVE-2023-2702 HIGH
Finexmedia Competition Management System < 23.07 - IDOR
CVSS 8.8
CVE-2023-2844 MEDIUM
GitHub cloudexplorer-dev/cloudexplorer-lite <v1.1.0 - Auth Bypass
CVSS 4.9
CVE-2023-2713 CRITICAL
Rental Module < 23.05.15 - IDOR
CVSS 9.8
CVE-2023-2276 CRITICAL
Wclovers Wcfm Membership < 2.10.7 - IDOR
CVSS 9.8
CVE-2023-2548 MEDIUM
Metagauss Registrationmagic < 5.2.0.5 - IDOR
CVSS 6.6
CVE-2023-31182 HIGH
EasyTor Applications - Auth Bypass
CVSS 8.1
CVE-2023-30216 MEDIUM
Newbee-mall < 2022-10-27 - IDOR
CVSS 5.4
CVE-2023-30550 MEDIUM
Metersphere < 2.9.0 - IDOR
CVSS 6.8
CVE-2023-28656 HIGH
NGINX Management Suite - Privilege Escalation
CVSS 8.1
CVE-2023-1911 MEDIUM
Blocksy Companion <1.8.82 - Info Disclosure
CVSS 4.3
CVE-2023-1125 MEDIUM
Wpruby Ruby Help Desk < 1.3.4 - IDOR
CVSS 6.5
CVE-2023-2260 HIGH
Alf < 2.0-m4-2304 - IDOR
CVSS 8.8
CVE-2023-1417 MEDIUM
GitLab <15.9.4-15.10.1 - Info Disclosure
CVSS 4.3
CVE-2023-0967 MEDIUM
Imaworldhealth Bhima - IDOR
CVSS 6.5
CVE-2023-1750 HIGH
Nexx Smart Home - Privilege Escalation
CVSS 7.1
CVE-2023-1749 MEDIUM
Nexx Smart Home - Code Injection
CVSS 6.5
CVE-2023-26984 HIGH
Peppermint <0.2.4 - Info Disclosure
CVSS 8.1
CVE-2023-24842 MEDIUM
HGiga MailSherlock - Info Disclosure
CVSS 5.3
CVE-2023-24834 MEDIUM
WisdomGarden Tronclass - Privilege Escalation
CVSS 6.5
CVE-2023-24625 MEDIUM
Faveo 5.0.1 - Info Disclosure
CVSS 6.5
CVE-2023-28686 HIGH
Dino <0.2.3, 0.3.x <0.3.2, 0.4.x <0.4.2 - Info Disclosure
CVSS 7.1
CVE-2023-28334 MEDIUM
Moodle < 4.0.7 - Information Disclosure
CVSS 4.3
Details
Vulnerabilities 1,575
Exploit Likelihood High