VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,334)

page 21 of 117
  • CVE-2024-8040HigOct 16, 2024
    risk 0.50cvss 7.7epss 0.00

    An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

  • CVE-2024-8290HigSep 25, 2024
    risk 0.50cvss 8.8epss 0.01

    The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function…

  • CVE-2024-8428HigSep 6, 2024
    risk 0.50cvss 8.8epss 0.00

    The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key.…

  • CVE-2023-3289HigJul 9, 2024
    risk 0.50cvss 7.7epss 0.00

    A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.

  • CVE-2023-3286HigJul 9, 2024
    risk 0.50cvss 7.7epss 0.00

    A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.

  • CVE-2023-3285HigJul 9, 2024
    risk 0.50cvss 7.7epss 0.00

    A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.

  • CVE-2022-4803HigDec 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2020-13700HigJun 24, 2020
    risk 0.50cvss 7.5epss 0.13

    An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as…

  • CVE-2020-8154HigMay 12, 2020
    risk 0.50cvss 7.7epss 0.02

    An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

  • CVE-2026-19870HigAug 14, 2026
    risk 0.49cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users…

  • CVE-2026-19734HigAug 13, 2026
    risk 0.49cvss epss 0.00

    Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another…

  • CVE-2026-72545HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before…

  • CVE-2026-72543HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or…

  • CVE-2026-19424HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.

  • CVE-2026-19433HigAug 10, 2026
    risk 0.49cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a…

  • CVE-2026-72689HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the…

  • CVE-2026-13399HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

  • CVE-2026-10599HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to…

  • CVE-2026-65523HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.

  • CVE-2026-43977HigJul 16, 2026
    risk 0.49cvss 7.5epss 0.00

    wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ actions on a routine they do not own. The…