VYPR

CWE-566

Authorization Bypass Through User-Controlled SQL Primary Key

VariantIncomplete

Description

The product uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8)

  • CVE-2025-9953CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 2026/04.

  • CVE-2014-0808CriJan 22, 2014
    risk 0.59cvss 9.1epss 0.02

    Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a…

  • CVE-2025-61781HigJan 5, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as dashboards and investigation cases.…

  • CVE-2026-21886MedMar 17, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualDeletionDeleteMutation" is intended to allow users to delete individual entity objects respectively. However, it was…

  • CVE-2025-56556LowSep 11, 2025
    risk 0.25cvss 3.8epss 0.00

    An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

  • CVE-2025-30369LowMar 31, 2025
    risk 0.18cvss 2.7epss 0.00

    Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an…

  • CVE-2024-22261LowJun 11, 2024
    risk 0.18cvss 2.7epss 0.00

    SQL-Injection in Harbor allows priviledge users to leak the task IDs

  • CVE-2025-30368LowMar 31, 2025
    risk 0.00cvss 2.7epss 0.00

    Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of…