VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,334)

page 3 of 117
  • CVE-2024-11284CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the…

  • CVE-2024-10215CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it…

  • CVE-2024-50483CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.02

    Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

  • CVE-2024-8485CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be…

  • CVE-2024-27113CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV…

  • CVE-2024-8292CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.01

    The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This…

  • CVE-2023-3287CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation.

  • CVE-2023-38054CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2023-38053CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2023-38052CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2023-38051CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2023-38049CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2023-38048CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2024-39223CriJul 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

  • CVE-2024-1107CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Travel APPS: before v17.0.68.

  • CVE-2023-38965CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

  • CVE-2023-2958CriJul 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass. This issue affects ATS Pro: before 20230714.

  • CVE-2023-37242CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.

  • CVE-2023-3048CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2023-2713CriMay 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23.05.15.