VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 61 of 115
  • CVE-2020-5194MedJan 14, 2020
    risk 0.35cvss 5.4epss 0.01

    The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is…

  • CVE-2019-8235MedOct 30, 2019
    risk 0.35cvss 6.5epss 0.02

    An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation…

  • CVE-2019-7872MedAug 2, 2019
    risk 0.35cvss 6.5epss 0.01

    An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to insufficient authorizations checks. This can be abused by a user with admin privileges to add users to company accounts…

  • CVE-2019-5966MedJul 5, 2019
    risk 0.35cvss 5.4epss 0.01

    Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose the information via unspecified vectors.

  • CVE-2019-10108MedMay 15, 2019
    risk 0.35cvss 5.4epss 0.01

    An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.

  • CVE-2018-18976MedMay 6, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user ID values.…

  • CVE-2019-9170MedApr 17, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.

  • CVE-2019-9938MedMar 22, 2019
    risk 0.35cvss 5.3epss 0.01

    The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to download arbitrary files from the device including contacts, photos, videos,…

  • CVE-2018-10211MedApr 25, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie.

  • CVE-2026-72802MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to…

  • CVE-2026-16737MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order…

  • CVE-2026-15147MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated…

  • CVE-2026-14842MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.

  • CVE-2026-28180MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

  • CVE-2026-14313MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is…

  • CVE-2026-16981MedAug 5, 2026
    risk 0.34cvss 5.3epss 0.00

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and…

  • CVE-2026-3482MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP…

  • CVE-2026-54105MedJun 18, 2026
    risk 0.34cvss 5.3epss 0.01

    The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated…

  • CVE-2026-53911MedJun 11, 2026
    risk 0.34cvss epss 0.00

    Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did not explicitly mark id as inaccessible, an authenticated attacker could submit…

  • CVE-2023-40200MedJun 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from…