VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 59 of 115
  • CVE-2022-4812MedDec 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4799MedDec 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-3794MedDec 22, 2022
    risk 0.35cvss 5.4epss 0.01

    The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as…

  • CVE-2022-40205MedNov 8, 2022
    risk 0.35cvss 5.4epss 0.00

    Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.

  • CVE-2022-39945MedNov 2, 2022
    risk 0.35cvss 5.4epss 0.00

    An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct…

  • CVE-2022-36966MedOct 20, 2022
    risk 0.35cvss 5.4epss 0.00

    Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

  • CVE-2022-2312MedAug 22, 2022
    risk 0.35cvss 5.4epss 0.00

    The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of…

  • CVE-2022-2535MedAug 15, 2022
    risk 0.35cvss 5.3epss 0.02

    The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

  • CVE-2022-1600MedAug 1, 2022
    risk 0.35cvss 5.3epss 0.01

    The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

  • CVE-2022-27247MedMay 13, 2022
    risk 0.35cvss 5.3epss 0.01

    onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.

  • CVE-2022-1352MedMay 11, 2022
    risk 0.35cvss 5.3epss 0.01

    Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a…

  • CVE-2022-26254MedMar 27, 2022
    risk 0.35cvss 5.3epss 0.01

    WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

  • CVE-2022-0731MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2022-24979MedFeb 19, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct…

  • CVE-2022-25336MedFeb 18, 2022
    risk 0.35cvss 5.3epss 0.01

    Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.

  • CVE-2022-0613MedFeb 16, 2022
    risk 0.35cvss 6.5epss 0.02

    Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

  • CVE-2021-25096MedFeb 7, 2022
    risk 0.35cvss 6.5epss 0.01

    The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

  • CVE-2022-23856MedJan 24, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.

  • CVE-2021-3992MedDec 1, 2021
    risk 0.35cvss 6.5epss 0.01

    kimai2 is vulnerable to Improper Access Control

  • CVE-2021-24840MedNov 8, 2021
    risk 0.35cvss 5.3epss 0.01

    The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.