VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 44 of 115
  • CVE-2023-2173MedAug 31, 2023
    risk 0.42cvss 6.5epss 0.01

    The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_delete_step_ajax_handler, badgeos_delete_award_step_ajax_handler,…

  • CVE-2023-32078HigAug 24, 2023
    risk 0.42cvss 7.5epss 0.01

    Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in the user update function. By specifying another user's username, it was possible to update the other user's password. The issue is…

  • CVE-2023-2190MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork…

  • CVE-2023-26428MedJun 20, 2023
    risk 0.42cvss 6.5epss 0.01

    Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not…

  • CVE-2023-0694MedJun 9, 2023
    risk 0.42cvss 6.5epss 0.01

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about…

  • CVE-2023-0693MedJun 9, 2023
    risk 0.42cvss 6.5epss 0.01

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction_id' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive…

  • CVE-2023-0688MedJun 9, 2023
    risk 0.42cvss 6.5epss 0.01

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive…

  • CVE-2023-1125MedMay 2, 2023
    risk 0.42cvss 6.5epss 0.01

    The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

  • CVE-2022-48313MedApr 16, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-45175MedApr 14, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffice backend of other users by…

  • CVE-2023-0967MedApr 5, 2023
    risk 0.42cvss 6.5epss 0.01

    Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly…

  • CVE-2023-1749MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute.

  • CVE-2023-24834MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL.

  • CVE-2023-24625MedMar 24, 2023
    risk 0.42cvss 6.5epss 0.01

    Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.

  • CVE-2021-36539MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).

  • CVE-2022-38765MedDec 9, 2022
    risk 0.42cvss 6.5epss 0.00

    Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

  • CVE-2022-2828MedOct 13, 2022
    risk 0.42cvss 6.5epss 0.01

    In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability

  • CVE-2022-34621MedAug 19, 2022
    risk 0.42cvss 6.5epss 0.01

    Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.

  • CVE-2022-36284MedAug 5, 2022
    risk 0.42cvss 6.4epss 0.01

    Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile…

  • CVE-2022-33944MedJul 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs.