CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2022-4803 HIGH
usememos/memos <0.9.1 - Auth Bypass
CVSS 8.8
CVE-2022-4802 MEDIUM
GitHub usememos/memos <0.9.1 - Auth Bypass
CVSS 5.4
CVE-2022-4799 MEDIUM
Memos < 0.9.1 - IDOR
CVSS 6.5
CVE-2022-4798 MEDIUM
Memos < 0.9.1 - IDOR
CVSS 5.3
CVE-2022-46179 CRITICAL
LiuOS <0.1.0 - Auth Bypass
CVSS 9.2
CVE-2022-4686 CRITICAL
GitHub repository usememos/memos <0.9.0 - Auth Bypass
CVSS 9.8
CVE-2022-3805 HIGH
Jeg Elementor Kit <2.5.6 - Auth Bypass
CVSS 8.6
CVE-2022-3794 MEDIUM
Jeg Elementor Kit <2.5.6 - Auth Bypass
CVSS 5.4
CVE-2022-31683 MEDIUM
Pivotal Software Concourse < 6.7.9 - IDOR
CVSS 5.4
CVE-2022-3876 MEDIUM
Click Studios Passwordstate - Auth Bypass
CVSS 4.3
CVE-2022-4505 HIGH
Open-emr Openemr < 7.0.0.2 - IDOR
CVSS 8.8
CVE-2022-4097 MEDIUM
All-In-One Security (AIOS) <5.0.8 - Open Redirect
CVSS 5.3
CVE-2022-38765 MEDIUM
Canon Medical Informatics Vitrea Vision <7.7.76.1 - Privilege Escal...
CVSS 6.5
CVE-2022-2808 HIGH
Algan Software Prens <2.1.11 - ORM Injection
CVSS 8.8
CVE-2022-3995 MEDIUM
Standalonetech Terawallet < 1.4.3 - IDOR
CVSS 4.3
CVE-2022-43326 HIGH
Telos Alliance Omnia MPX Node <1.4 - IDOR
CVSS 7.5
CVE-2022-24187 HIGH
Ourphoto App 1.4.1 - Info Disclosure
CVSS 7.5
CVE-2022-3589 HIGH
Miele AppWash - Auth Bypass
CVSS 8.1
CVE-2022-43492 MEDIUM
wpDiscuz 7.4.2 - Info Disclosure
CVSS 4.3
CVE-2022-44005 MEDIUM
BACKCLICK Professional 5.9.63 - Info Disclosure
CVSS 5.3
CVE-2022-42129 MEDIUM
Liferay Digital Experience Platform < 7.4.3.5 - IDOR
CVSS 4.3
CVE-2022-3413 MEDIUM
Gitlab < 15.3.5 - IDOR
CVSS 4.3
CVE-2022-40206 MEDIUM
Gvectors Wpforo Forum < 2.0.5 - IDOR
CVSS 6.3
CVE-2022-40205 MEDIUM
Gvectors Wpforo Forum < 2.0.5 - IDOR
CVSS 5.4
CVE-2022-39945 MEDIUM
Fortinet Fortimail < 6.0.12 - IDOR
CVSS 5.4
Details
Vulnerabilities 1,575
Exploit Likelihood High