VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,334)

page 11 of 117
  • CVE-2023-6724HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse. This issue affects Hearing Tracking System: before for IOS 7.0, for Android Latest release…

  • CVE-2023-6515HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-MED: before 1.0.7.

  • CVE-2023-49251HigJan 9, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take…

  • CVE-2023-45380HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.01

    In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal…

  • CVE-2023-46478HigOct 30, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

  • CVE-2022-24401HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.00

    Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthenticated manner. An active adversary can…

  • CVE-2023-43668CriOct 16, 2023
    risk 0.57cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... .   Users are advised to upgrade…

  • CVE-2023-38218HigOct 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and privilege escalation.

  • CVE-2023-4101HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.00

    The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

  • CVE-2023-4934HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication Bypass. This issue affects AYBS: before 1.0.3.

  • CVE-2023-4213HigSep 13, 2023
    risk 0.57cvss 8.8epss 0.01

    The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system…

  • CVE-2020-10130HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.01

    SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.

  • CVE-2023-28481HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key…

  • CVE-2023-3105HigJul 12, 2023
    risk 0.57cvss 8.8epss 0.02

    The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes…

  • CVE-2022-42175HigJul 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other customer servers without authorization.

  • CVE-2023-3063HigJun 30, 2023
    risk 0.57cvss 8.8epss 0.01

    The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system…

  • CVE-2021-33223HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.

  • CVE-2023-0985HigJun 6, 2023
    risk 0.57cvss 8.8epss 0.01

    An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to…

  • CVE-2023-2883HigMay 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2023-2065HigMay 24, 2023
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass. This issue affects Cargo Tracking System: before 3558f28 .