CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,830 vulnerabilities with CWE-639
CVE-2020-11658 CRITICAL
CA API Developer Portal < 4.3.1 - Authorization Bypass via Shared Secret Key
CVSS 9.8
CVE-2020-9384 HIGH
Subex ROC Partner Settlement 10.5 - Authenticated Account Takeover via Change Password IDOR
CVSS 8.8
CVE-2020-11589 HIGH
CIPPlanner CIPAce < 9.1 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
CVE-2020-11585 MEDIUM
Dnnsoftware Dotnetnuke - Information Disclosure
CVSS 4.3
CVE-2020-7918 MEDIUM
Totemo totemomail 7.0.0 - Info Disclosure
CVSS 5.4
CVE-2020-9468 MEDIUM
Piwigo Community plugin 2.9.e-beta - Authorization Bypass via Image ID Parameter
CVSS 4.3
CVE-2020-5539 MEDIUM
GRANDIT 1.6-3.0 - Authentication Bypass via Session Impersonation
CVSS 6.5
CVE-2020-8503 MEDIUM
Biscom SFT <5.1.1067, <6.0.1003 - IDOR
CVSS 6.5
CVE-2020-5194 MEDIUM
Cerberus FTP Server 8 - Authenticated Authorization Bypass via Zip API Endpoint
CVSS 5.4
CVE-2020-6859 MEDIUM
Ultimate Member < 2.1.2 - Insecure Direct Object Reference via user_id Parameter
CVSS 5.3
CVE-2019-25487 CRITICAL
Sapido RB-1732 2.0.43 - Unauthenticated Remote Code Execution via formSysCmd Endpoint
CVSS 9.8
CVE-2019-25235 CRITICAL
Smartwares HOME easy <1.0.9 - Auth Bypass
CVSS 9.8
CVE-2019-19755 CRITICAL
ethOS <= 1.3.3 - SSH Host Key Reuse
CVSS 9.1
CVE-2019-15310 CRITICAL
Linkplay - Unauthenticated Remote Code Execution via XML Parsing in Firmware Update
CVSS 9.8
CVE-2019-18626 MEDIUM
Harris Ormed Self Service <2019.1.4 - Info Disclosure
CVSS 4.3
CVE-2019-19946 MEDIUM
Dradis Pro 3.4.1 - Authorization Bypass via Project Content Extraction
CVSS 6.5
CVE-2019-19866 HIGH
Atos Unify OpenScape UC Web Client V9 < R4.31.0 & V10 < R0.6.0 - Sensitive Info Disclosure via Conference ID Enumeration
CVSS 7.5
CVE-2019-18998 HIGH
ABB Asset Suite <9.4.2.6-9.6.0 - Info Disclosure
CVSS 7.1
CVE-2019-5466 MEDIUM
GitLab 11.5.0-11.11.7 - Authorization Bypass via Merge Request Endpoint
CVSS 4.3
CVE-2019-15582 MEDIUM
GitLab < 12.3.2, < 12.2.6, < 12.1.12 - Authorization Bypass via Protected Environment Group Addition
CVSS 5.3
CVE-2019-15581 MEDIUM
GitLab < 12.3.2, < 12.2.6, < 12.1.12 - Insecure Direct Object Reference via Merge Request Approval Rules
CVSS 5.3
CVE-2019-20209 HIGH
CTHthemes CityBook, TownHub, and EasyBook - Insecure Direct Object Reference via admin-ajax.php
CVSS 7.5
CVE-2019-19259 MEDIUM
GitLab 11.3.0-12.5.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2019-15913 CRITICAL
Xiaomi Devices - Info Disclosure/DoS
CVSS 9.8
CVE-2019-5469 MEDIUM
GitLab < 11.11.6, < 12.0.4, < 12.1.2 - Authorization Bypass via Project Archive File Upload
CVSS 6.5
Details
Vulnerabilities 1,830
Exploit Likelihood High