CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,822 vulnerabilities with CWE-639
CVE-2023-30059 MEDIUM
MK-Auth 23.01K4.9 - Insecure Direct Object Reference
CVSS 5.4
CVE-2023-36331 HIGH
xmall v1.1 - Unauthenticated Authorization Bypass via /member/orderList userId Parameter
CVSS 8.2
CVE-2023-53955 CRITICAL
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Auth Bypass
CVSS 9.8
CVE-2023-53930 HIGH
ProjectSend r1605 - Info Disclosure
CVSS 7.5
CVE-2023-53914 CRITICAL
UliCMS 2023.1 - Unauthenticated Authentication Bypass via Mass Assignment in UserController
CVSS 9.8
CVE-2023-47543 MEDIUM
FortiPortal 7.0.0-7.0.3 - Authenticated Authorization Bypass via HTTP/HTTPS Requests
CVSS 5.4
CVE-2023-32189 MEDIUM
Product <Version - Local Privilege Escalation
CVSS 5.9
CVE-2023-7286 MEDIUM
ACF Quick Edit Fields <3.2.2 - Info Disclosure
CVSS 6.5
CVE-2023-44254 MEDIUM
FortiAnalyzer and FortiManager < 7.2.5 - Authorization Bypass via Crafted HTTP Request
CVSS 5.0
CVE-2023-7049 MEDIUM
Custom Field For WP Job Manager <1.3 - Insecure Direct Object Refer...
CVSS 4.3
CVE-2023-3290 MEDIUM
easyappointments < 1.5.0 - Authorization Bypass via POST /customers
CVSS 5.0
CVE-2023-3289 HIGH
easyappointments < 1.5.0 - Authorization Bypass via POST /services
CVSS 7.7
CVE-2023-3288 HIGH
easyappointments < 1.5.0 - Privilege Escalation via POST /providers
CVSS 8.5
CVE-2023-3287 CRITICAL
easyappointments < 1.5.0 - Privilege Escalation via POST /admins
CVSS 9.9
CVE-2023-3286 HIGH
easyappointments < 1.5.0 - Unauthenticated Broken Access Control via Secretary Creation
CVSS 7.7
CVE-2023-38055 CRITICAL
easyappointments < 1.5.0 - Authenticated Authorization Bypass via Service ID Manipulation
CVSS 9.6
CVE-2023-38054 CRITICAL
easyappointments < 1.5.0 - Unauthenticated Broken Object Level Authorization via Customer ID Manipulation
CVSS 9.9
CVE-2023-38053 CRITICAL
easyappointments < 1.5.0 - Authenticated Authorization Bypass via Settings Endpoint
CVSS 9.9
CVE-2023-38052 CRITICAL
easyappointments < 1.5.0 - Authorization Bypass via Admin ID Manipulation
CVSS 9.9
CVE-2023-38051 CRITICAL
easyappointments < 1.5.0 - Unauthorized Access and Data Manipulation via Secretary ID Parameter
CVSS 9.9
CVE-2023-38050 CRITICAL
easyappointments < 1.5.0 - Unauthenticated Broken Object Level Authorization via Webhook ID Manipulation
CVSS 9.1
CVE-2023-38049 CRITICAL
easyappointments < 1.5.0 - Authenticated Broken Object Level Authorization via Appointment ID Manipulation
CVSS 9.9
CVE-2023-38048 CRITICAL
easyappointments < 1.5.0 - Unauthenticated Authorization Bypass via Provider ID Manipulation
CVSS 9.9
CVE-2023-38047 HIGH
easyappointments < 1.5.0 - Unauthorized Data Access and Manipulation via Category Endpoint
CVSS 8.5
CVE-2023-3285 HIGH
easyappointments < 1.5.0 - Authorization Bypass via Appointment Creation
CVSS 7.7
Details
Vulnerabilities 1,822
Exploit Likelihood High