CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,827 vulnerabilities with CWE-639
CVE-2022-1996 CRITICAL
emicklei/go-restful <3.8.0 - Auth Bypass
CVSS 9.1
CVE-2022-29627 MEDIUM
Online Market Place Site 1.0 - Authorization Bypass via Insecure Direct Object Reference
CVSS 4.3
CVE-2022-1949 HIGH
389 Directory Server - Unauthenticated Access Control Bypass via Filter Mishandling
CVSS 7.5
CVE-2022-30495 CRITICAL
Automotive Shop Management System 1.0 - Unauthenticated Vertical Privilege Escalation via IDOR in Name ID Parameter
CVSS 9.8
CVE-2022-1810 MEDIUM
Publify < 9.2.9 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2022-29434 MEDIUM
Spiffy Calendar <= 4.9.0 - Insecure Direct Object Reference in Event Editing
CVSS 6.3
CVE-2022-29159 MEDIUM
Nextcloud Deck <1.4.8-1.6.1 - Privilege Escalation
CVSS 5.0
CVE-2022-1425 MEDIUM
WPQA Builder Plugin < 5.2 - Unauthenticated Insecure Direct Object Reference via wpqa_message_view AJAX Action
CVSS 4.3
CVE-2022-27247 MEDIUM
cdSoft Onlinetools-Smart Winhotel.MX 2021 - Sensitive Information Disclosure via GastKont IDOR
CVSS 5.3
CVE-2022-1352 MEDIUM
GitLab 11.0-14.8.6, 14.9-14.9.4, 14.10-14.10.1 - Insecure Direct Object Reference in Issue API
CVSS 5.3
CVE-2022-29008 MEDIUM
Bus Pass Management System v1.0 - Info Disclosure
CVSS 6.5
CVE-2022-28986 HIGH
LMS Doctor Simple <2021072900 - IDOR
CVSS 7.5
CVE-2022-23061 MEDIUM
Shopizer 2.0-2.17.0 - Insecure Direct Object Reference to Superadmin Deletion
CVSS 6.5
CVE-2022-1461 MEDIUM
OpenEMR < 6.1.0.1 - Insufficient Access Control for User Registration Settings
CVSS 6.5
CVE-2022-1459 HIGH
openemr/openemr <6.1.0.1 - Info Disclosure
CVSS 8.3
CVE-2022-26665 HIGH
Tyler Odyssey Portal <17.1.20 - Info Disclosure
CVSS 7.5
CVE-2022-29287 MEDIUM
Kentico CMS <13.0.66 - Info Disclosure
CVSS 4.9
CVE-2022-22190 HIGH
Juniper Paragon Active Assurance Control Center 3.1.0 - Unauthenticated Sensitive Data Exposure
CVSS 7.4
CVE-2022-27108 MEDIUM
OrangeHRM 4.10 - Insecure Direct Object Reference in Timesheet Creation
CVSS 4.3
CVE-2022-1165 CRITICAL
Blackhole for Bad Bots < 3.3.2 - IP Spoofing via Custom Headers
CVSS 9.1
CVE-2022-22331 HIGH
IBM SterlingPartner Engagement Manager 6.2.0 - Info Disclosure
CVSS 7.1
CVE-2022-26254 MEDIUM
WoWonder 4.0.0 - Unauthenticated Group Name Modification
CVSS 5.3
CVE-2022-0442 MEDIUM
UsersWP < 1.2.3.1 - Authenticated Arbitrary Avatar Overwrite via Missing Access Controls
CVSS 4.3
CVE-2022-25471 HIGH
OpenEMR 6.0.0 - Authenticated Insecure Direct Object Reference via Installer Module
CVSS 8.1
CVE-2022-0732 HIGH
1byte copy9 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
Details
Vulnerabilities 1,827
Exploit Likelihood High