VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 137 of 138
  • CVE-2025-58055MedOct 1, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to…

  • CVE-2025-7106MedSep 23, 2025
    risk 0.00cvss 5.3epss 0.00

    danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/server/middleware/roles/access.js` uses `permissions.some()` to validate permissions, which incorrectly grants access if only one…

  • CVE-2025-53944HigJul 30, 2025
    risk 0.00cvss 7.7epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_results endpoint has an authorization bypass vulnerability. While it correctly validates user access to…

  • CVE-2025-51479MedJul 22, 2025
    risk 0.00cvss 5.4epss 0.00

    Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment…

  • CVE-2025-49135MedJun 25, 2025
    risk 0.00cvss 6.5epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or task backup to check that the filename specified in the query parameter refers to a TUS-uploaded…

  • CVE-2024-8613HigMar 20, 2025
    risk 0.00cvss 8.8epss 0.01

    A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate…

  • CVE-2024-7040Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-11167MedMar 20, 2025
    risk 0.00cvss 5.3epss 0.01

    An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the…

  • CVE-2024-10366MedMar 20, 2025
    risk 0.00cvss 6.5epss 0.00

    An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete…

  • CVE-2024-50633NonJan 16, 2025
    risk 0.00cvss 0.0epss 0.01

    A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users…

  • CVE-2024-52511MedNov 15, 2024
    risk 0.00cvss 6.3epss 0.00

    Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.

  • CVE-2024-52507LowNov 15, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded…

  • CVE-2024-27730CriAug 15, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.

  • CVE-2024-7658MedAug 12, 2024
    risk 0.00cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely.…

  • CVE-2024-37889MedJun 14, 2024
    risk 0.00cvss 6.5epss 0.01

    MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6.

  • CVE-2024-36399HigJun 6, 2024
    risk 0.00cvss 8.2epss 0.00

    Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is…

  • CVE-2023-45808MedApr 15, 2024
    risk 0.00cvss 4.1epss 0.00

    iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an…

  • CVE-2023-36235MedJan 17, 2024
    risk 0.00cvss 6.5epss 0.01

    An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.

  • CVE-2023-49298HigNov 24, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always…

  • CVE-2023-48304MedNov 21, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11,…