VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 113 of 115
  • CVE-2024-52507LowNov 15, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded…

  • CVE-2024-27730CriAug 15, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.

  • CVE-2024-7658MedAug 12, 2024
    risk 0.00cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely.…

  • CVE-2024-37889MedJun 14, 2024
    risk 0.00cvss 6.5epss 0.01

    MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6.

  • CVE-2024-36399HigJun 6, 2024
    risk 0.00cvss 8.2epss 0.00

    Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is…

  • CVE-2023-45808MedApr 15, 2024
    risk 0.00cvss 4.1epss 0.00

    iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an…

  • CVE-2023-36235MedJan 17, 2024
    risk 0.00cvss 6.5epss 0.01

    An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.

  • CVE-2023-49298HigNov 24, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always…

  • CVE-2023-48304MedNov 21, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11,…

  • CVE-2023-42455HigOct 9, 2023
    risk 0.00cvss 8.8epss 0.01

    Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become…

  • CVE-2023-27576MedAug 18, 2023
    risk 0.00cvss 6.7epss 0.00

    An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission. Specifically, for a request with…

  • CVE-2023-33956MedJun 5, 2023
    risk 0.00cvss 4.3epss 0.01

    Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direct object reference (IDOR) vulnerability present in the application's URL parameter. This vulnerability enables any user to read…

  • CVE-2023-2844MedMay 23, 2023
    risk 0.00cvss 4.9epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

  • CVE-2023-2260HigApr 24, 2023
    risk 0.00cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

  • CVE-2023-25160MedFeb 13, 2023
    risk 0.00cvss 4.1epss 0.00

    Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25,…

  • CVE-2023-22471LowJan 14, 2023
    risk 0.00cvss 3.5epss 0.01

    Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the…

  • CVE-2022-46179CriDec 28, 2022
    risk 0.00cvss 9.2epss 0.00

    LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is…

  • CVE-2022-4505HigDec 15, 2022
    risk 0.00cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

  • CVE-2022-3019HigAug 29, 2022
    risk 0.00cvss 8.8epss 0.01

    The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

  • CVE-2021-4142MedAug 24, 2022
    risk 0.00cvss 5.5epss 0.00

    The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.