CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,830 vulnerabilities with CWE-639
CVE-2018-16608 HIGH
Monstra CMS 3.0.4 - Authorization Bypass via Insecure Direct Object Reference
CVSS 8.8
CVE-2018-16704 MEDIUM
Gleez CMS <1.2.0 - Info Disclosure
CVSS 4.3
CVE-2018-16606 MEDIUM
ProConf < 6.1 - Unauthenticated Insecure Direct Object Reference via Paper ID Parameter
CVSS 6.5
CVE-2018-15833 MEDIUM
Vanilla Forums < 2.6.1 - Insecure Direct Object Reference via Poll ID
CVSS 4.3
CVE-2018-1000210 HIGH
YamlDotNet < 5.0.0 - Deserialization of Untrusted Data via Type Name in Tag
CVSS 7.8
CVE-2018-10211 MEDIUM
Vaultize Enterprise File Sharing <17.05.31 - Info Disclosure
CVSS 5.3
CVE-2017-20223 CRITICAL
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
CVSS 9.8
CVE-2017-20101 LOW
ProjectSend r754 - Information Disclosure via process.php Zip Download
CVSS 3.5
CVE-2017-3183 HIGH
Sage XRT Treasury 3 - Authenticated Authorization Bypass via USER_CODE Manipulation
CVSS 8.8
CVE-2017-0936 MEDIUM
Nextcloud Server <11.0.7, 12.0.5 - Auth Bypass
CVSS 5.7
CVE-2017-0920 MEDIUM
GitLab <10.1.6, 10.2.6, 10.3.4 - Auth Bypass
CVSS 4.3
CVE-2017-0922 HIGH
GitLab 9.1.0-9.5.10 - Authorization Bypass in Projects::BoardsController
CVSS 7.5
CVE-2017-15211 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15209 MEDIUM
Kanboard - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15208 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15207 MEDIUM
Kanboard - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15206 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Internal Link Injection
CVSS 4.3
CVE-2017-15204 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Automatic Action Form Manipulation
CVSS 4.3
CVE-2017-15203 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15202 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15201 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Tag Editing
CVSS 4.3
CVE-2017-15200 MEDIUM
Kanboard - Authenticated Authorization Bypass via Task Form Manipulation
CVSS 4.3
CVE-2017-15199 MEDIUM
Kanboard < 1.0.47 - Authenticated Metadata Modification via Form Data Manipulation
CVSS 4.3
CVE-2017-15197 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Category Addition
CVSS 4.3
CVE-2017-15196 MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
Details
Vulnerabilities 1,830
Exploit Likelihood High