CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,822 vulnerabilities with CWE-639
CVE-2023-26237 MEDIUM
WatchGuard EPDR <8.0.21.0002 - Privilege Escalation
CVSS 6.7
CVE-2023-2544 MEDIUM
UPV PEIX - Authenticated Authorization Bypass via pdf_curri_new.php ID Parameter
CVSS 5.3
CVE-2023-32669 MEDIUM
BuddyBoss 2.2.9 - Insecure Direct Object Reference in User Albums
CVSS 5.4
CVE-2023-4101 HIGH
QSige SSO - Missing Access Control on Resource Requests
CVSS 8.8
CVE-2023-4099 HIGH
QSige Monitor - Authenticated Authorization Bypass Through User-Controlled Key
CVSS 7.6
CVE-2023-38872 LOW
gugoan Economizzer <0.9-beta1 - IDOR
CVSS 3.7
CVE-2023-4934 HIGH
Usta AYBS < 1.0.3 - Authentication Bypass via User-Controlled Key
CVSS 8.8
CVE-2023-44206 CRITICAL
Acronis Cyber Protect 15 < build 35979 - Sensitive Information Disclosure and Manipulation
CVSS 9.1
CVE-2023-44205 MEDIUM
Acronis Cyber Protect 15 < 35979 - Sensitive Information Disclosure via Improper Authorization
CVSS 5.3
CVE-2023-44154 HIGH
Acronis Cyber Protect <35979 - Info Disclosure
CVSS 8.1
CVE-2023-42334 MEDIUM
fl3xx Crew and Dispatch 2.10.37 - Authorization Bypass via User Parameter
CVSS 6.5
CVE-2023-4213 HIGH
Simplr Registration Form Plus+ <2.4.5 - Info Disclosure
CVSS 8.8
CVE-2023-41368 LOW
S4 HANA Manage checkbook apps <108 - SSRF
CVSS 2.7
CVE-2023-4587 HIGH
ZKTeco ZEM800 <6.60 - Info Disclosure
CVSS 8.3
CVE-2023-2173 MEDIUM
BadgeOS plugin <3.7.1.6 - Info Disclosure
CVSS 6.5
CVE-2023-2172 MEDIUM
BadgeOS <= 3.7.1.6 - Authenticated Insecure Direct Object Reference in AJAX Step Handlers
CVSS 4.3
CVE-2023-0689 MEDIUM
Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated Information Disclosure via mf_first_name Shortcode
CVSS 4.3
CVE-2023-38201 MEDIUM
Keylime < 7.5.0 - Authorization Bypass via Challenge-Response Protocol
CVSS 6.5
CVE-2023-32078 HIGH
Netmaker < 0.17.1 and 0.18.0-0.18.5 - Insecure Direct Object Reference in User Update Function
CVSS 7.5
CVE-2023-27576 MEDIUM
phpList <3.6.14 - Super Admin Account Takeover via IDOR
CVSS 6.7
CVE-2023-28481 HIGH
Tigergraph Enterprise 3.7.0 - Info Disclosure
CVSS 8.8
CVE-2023-37543 HIGH
Cacti < 1.2.6 - Insecure Direct Object Reference via local_graph_id Parameter
CVSS 7.5
CVE-2023-2958 CRITICAL
Origin Software ATS Pro < 20230714 - Authentication Bypass via User-Controlled Key
CVSS 9.8
CVE-2023-3700 MEDIUM
easyappointments < 1.5.0 - Authorization Bypass Through User-Controlled Key
CVSS 6.3
CVE-2023-2190 MEDIUM
GitLab CE/EE <15.11.10-16.0.6-16.1.1 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 1,822
Exploit Likelihood High