VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 66 of 115
  • CVE-2025-30514MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

  • CVE-2025-30254MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.

  • CVE-2025-27938MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

  • CVE-2025-27568MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.

  • CVE-2025-24487MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can infer the existence of usernames in the system by querying an API.

  • CVE-2025-3537MedApr 13, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/update-user.php. The manipulation of the argument ID leads to improper authorization. It is possible to initiate the…

  • CVE-2024-10925MedMar 3, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

  • CVE-2025-26965MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.16.

  • CVE-2024-13719MedFeb 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13457MedJan 30, 2025
    risk 0.34cvss 5.3epss 0.00

    The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated…

  • CVE-2024-10779MedNov 9, 2024
    risk 0.34cvss 5.3epss 0.00

    The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated…

  • CVE-2024-10439MedOct 28, 2024
    risk 0.34cvss 5.3epss 0.00

    The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

  • CVE-2022-3459MedSep 14, 2024
    risk 0.34cvss 5.3epss 0.00

    The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated…

  • CVE-2024-43350MedAug 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.

  • CVE-2024-41254MedJul 31, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.

  • CVE-2024-4750MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request

  • CVE-2024-34383MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7.1.

  • CVE-2024-32823MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.4.

  • CVE-2024-32683MedApr 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

  • CVE-2024-31095MedMar 31, 2024
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0.