CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,830 vulnerabilities with CWE-639
CVE-2018-16608
HIGH
Monstra CMS 3.0.4 - Authorization Bypass via Insecure Direct Object Reference
CVSS 8.8
CVE-2018-16704
MEDIUM
Gleez CMS <1.2.0 - Info Disclosure
CVSS 4.3
CVE-2018-16606
MEDIUM
ProConf < 6.1 - Unauthenticated Insecure Direct Object Reference via Paper ID Parameter
CVSS 6.5
CVE-2018-15833
MEDIUM
Vanilla Forums < 2.6.1 - Insecure Direct Object Reference via Poll ID
CVSS 4.3
CVE-2018-1000210
HIGH
YamlDotNet < 5.0.0 - Deserialization of Untrusted Data via Type Name in Tag
CVSS 7.8
CVE-2018-10211
MEDIUM
Vaultize Enterprise File Sharing <17.05.31 - Info Disclosure
CVSS 5.3
CVE-2017-20223
CRITICAL
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
CVSS 9.8
CVE-2017-20101
LOW
ProjectSend r754 - Information Disclosure via process.php Zip Download
CVSS 3.5
CVE-2017-3183
HIGH
Sage XRT Treasury 3 - Authenticated Authorization Bypass via USER_CODE Manipulation
CVSS 8.8
CVE-2017-0936
MEDIUM
Nextcloud Server <11.0.7, 12.0.5 - Auth Bypass
CVSS 5.7
CVE-2017-0920
MEDIUM
GitLab <10.1.6, 10.2.6, 10.3.4 - Auth Bypass
CVSS 4.3
CVE-2017-0922
HIGH
GitLab 9.1.0-9.5.10 - Authorization Bypass in Projects::BoardsController
CVSS 7.5
CVE-2017-15211
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15209
MEDIUM
Kanboard - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15208
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15207
MEDIUM
Kanboard - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15206
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Internal Link Injection
CVSS 4.3
CVE-2017-15204
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Automatic Action Form Manipulation
CVSS 4.3
CVE-2017-15203
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15202
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
CVE-2017-15201
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Tag Editing
CVSS 4.3
CVE-2017-15200
MEDIUM
Kanboard - Authenticated Authorization Bypass via Task Form Manipulation
CVSS 4.3
CVE-2017-15199
MEDIUM
Kanboard < 1.0.47 - Authenticated Metadata Modification via Form Data Manipulation
CVSS 4.3
CVE-2017-15197
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Category Addition
CVSS 4.3
CVE-2017-15196
MEDIUM
Kanboard < 1.0.47 - Authenticated Authorization Bypass via Form Data Manipulation
CVSS 4.3
Details
Vulnerabilities
1,830
Exploit Likelihood
High