CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,822 vulnerabilities with CWE-639
CVE-2023-28109 MEDIUM
Play With Docker <= 0.0.2 - Authorization Bypass via CORS Misconfiguration
CVSS 6.5
CVE-2023-25403 HIGH
yf-exam 1.8.0 - Authentication Bypass via Fixed JWT Key
CVSS 7.5
CVE-2023-0882 HIGH
Kron Tech Single Connect < 2.16.1 - Authorization Bypass Through User-Controlled Key
CVSS 8.8
CVE-2023-25160 MEDIUM
Nextcloud Mail < 1.11.8 - Unauthenticated Email Metadata Exposure via Mailbox ID
CVSS 4.1
CVE-2023-0558 HIGH
ContentStudio plugin <1.2.5 - Auth Bypass
CVSS 8.2
CVE-2023-0550 HIGH
Quick Restaurant Menu <2.0.2 - Privilege Escalation
CVSS 8.1
CVE-2023-22471 LOW
Nextcloud Deck < 1.6.5 - Authorization Bypass via Attachment Deletion
CVSS 3.5
CVE-2022-3459 MEDIUM
WooCommerce Multiple Free Gift <= 1.2.3 - Unauthenticated Gift Manipulation via Missing Server-Side Checks
CVSS 5.3
CVE-2022-43450 MEDIUM
XWP Stream < 3.9.2 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2022-24401 HIGH
midnightblue tetra - Authorization Bypass Through User-Controlled Key via Keystream Reuse
CVSS 8.8
CVE-2022-24400 HIGH
midnightblue tetra - Authorization Bypass via Predictable MS Challenge RAND2
CVSS 7.5
CVE-2022-42175 HIGH
SolusVM 1 4.1.2 - Insecure Direct Object Reference in WHMCS Module
CVSS 8.8
CVE-2022-48505 MEDIUM
macOS < 13.0 - Unauthorized File System Modification
CVSS 5.5
CVE-2022-36247 CRITICAL
Shop Beat Media Player <3.2.57 - Open Redirect
CVSS 9.1
CVE-2022-48313 MEDIUM
Huawei EMUI and HarmonyOS - Bluetooth Pairing Authorization Bypass
CVSS 6.5
CVE-2022-45175 MEDIUM
LIVEBOX Collaboration vDesk < 018 - Unauthenticated Insecure Direct Object Reference via OnlyOffice WebSocket Endpoint
CVSS 6.5
CVE-2022-34138 HIGH
Biltema IP and Baby Camera Software <v124 - Info Disclosure
CVSS 7.5
CVE-2022-45927 HIGH
OpenText Extended ECM 20.4-22.3 - Unauthenticated Remote Code Execution via QDS Endpoint
CVSS 8.8
CVE-2022-40319 HIGH
LISTSERV 17 - Unauthenticated Account Modification via IDOR in wa.exe Email Parameter
CVSS 7.5
CVE-2022-4812 MEDIUM
GitHub repository usememos/memos <0.9.1 - Auth Bypass
CVSS 6.5
CVE-2022-4811 HIGH
usememos/memos <0.9.1 - Auth Bypass
CVSS 8.3
CVE-2022-4806 MEDIUM
GitHub usememos/memos <0.9.1 - Auth Bypass
CVSS 5.3
CVE-2022-4803 HIGH
usememos/memos <0.9.1 - Auth Bypass
CVSS 8.8
CVE-2022-4802 MEDIUM
GitHub usememos/memos <0.9.1 - Auth Bypass
CVSS 5.4
CVE-2022-4799 MEDIUM
memos < 0.9.1 - Authorization Bypass Through User-Controlled Key
CVSS 6.5
Details
Vulnerabilities 1,822
Exploit Likelihood High