VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 60 of 115
  • CVE-2021-29773MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.01

    IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865.

  • CVE-2021-37709MedAug 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3,…

  • CVE-2021-37212MedAug 9, 2021
    risk 0.35cvss 5.4epss 0.01

    The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.

  • CVE-2021-24473MedAug 2, 2021
    risk 0.35cvss 5.4epss 0.01

    The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).

  • CVE-2021-24374MedJun 21, 2021
    risk 0.35cvss 5.3epss 0.01

    The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the…

  • CVE-2021-21022MedFeb 11, 2021
    risk 0.35cvss 5.3epss 0.02

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricted resources.

  • CVE-2020-16194MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

  • CVE-2020-29446MedJan 18, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.

  • CVE-2021-21012MedJan 13, 2021
    risk 0.35cvss 5.3epss 0.04

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-29156MedDec 27, 2020
    risk 0.35cvss 5.3epss 0.04

    The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

  • CVE-2020-26178MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.01

    In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

  • CVE-2020-16240MedSep 23, 2020
    risk 0.35cvss 5.3epss 0.01

    GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have access to such functionality. An attacker can download…

  • CVE-2020-23446MedSep 22, 2020
    risk 0.35cvss 5.3epss 0.01

    Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API

  • CVE-2020-13923MedJul 15, 2020
    risk 0.35cvss 5.3epss 0.05

    IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

  • CVE-2020-13998MedJun 11, 2020
    risk 0.35cvss 5.3epss 0.01

    Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer…

  • CVE-2020-7918MedMar 27, 2020
    risk 0.35cvss 5.4epss 0.01

    An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

  • CVE-2019-15582MedJan 28, 2020
    risk 0.35cvss 5.3epss 0.01

    An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.

  • CVE-2019-15581MedJan 28, 2020
    risk 0.35cvss 5.3epss 0.01

    An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules.

  • CVE-2020-5194MedJan 14, 2020
    risk 0.35cvss 5.4epss 0.01

    The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is…

  • CVE-2019-8235MedOct 30, 2019
    risk 0.35cvss 6.5epss 0.02

    An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation…