VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,334)

page 6 of 117
  • CVE-2024-50686CriFeb 26, 2025
    risk 0.59cvss 9.1epss 0.00

    SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.

  • CVE-2024-50685CriFeb 26, 2025
    risk 0.59cvss 9.1epss 0.00

    SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.

  • CVE-2025-1270CriFeb 13, 2025
    risk 0.59cvss 9.1epss 0.00

    Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to…

  • CVE-2024-49388CriOct 15, 2024
    risk 0.59cvss 9.1epss 0.00

    Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2023-38050CriJul 9, 2024
    risk 0.59cvss 9.1epss 0.00

    A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

  • CVE-2024-2472CriJun 14, 2024
    risk 0.59cvss 9.1epss 0.01

    The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for…

  • CVE-2019-19755CriApr 30, 2024
    risk 0.59cvss 9.1epss 0.00

    ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.

  • CVE-2024-33668CriApr 26, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

  • CVE-2024-31815CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.01

    In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

  • CVE-2023-49583CriDec 12, 2023
    risk 0.59cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

  • CVE-2023-6144CriNov 21, 2023
    risk 0.59cvss 9.1epss 0.00

    Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.

  • CVE-2023-44981CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.02

    Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in…

  • CVE-2023-44206CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2022-36247CriMay 30, 2023
    risk 0.59cvss 9.1epss 0.01

    Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.

  • CVE-2022-40186CriSep 22, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an…

  • CVE-2022-38789CriSep 15, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.

  • CVE-2021-20599CriOct 14, 2021
    risk 0.59cvss 9.1epss 0.01

    Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11"…

  • CVE-2014-0808CriJan 22, 2014
    risk 0.59cvss 9.1epss 0.02

    Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a…

  • CVE-2026-55166CriAug 18, 2026
    risk 0.57cvss 9.9epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud…

  • CVE-2026-75103HigAug 17, 2026
    risk 0.57cvss 8.8epss 0.00

    Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve…