CWE-639
Authorization Bypass Through User-Controlled Key
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Hierarchy (View 1000)
CVEs mapped to this weakness (2,283)
page 82 of 115| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42067 | Med | 0.28 | 4.3 | 0.00 | Oct 14, 2022 | Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability | ||
| CVE-2022-1580 | Med | 0.28 | 4.3 | 0.01 | Sep 19, 2022 | The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature. | ||
| CVE-2022-2913 | Med | 0.28 | 4.3 | 0.01 | Sep 16, 2022 | The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen. | ||
| CVE-2022-2034 | Med | 0.28 | 5.3 | 0.02 | Aug 29, 2022 | The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers | ||
| CVE-2022-2198 | Med | 0.28 | 4.3 | 0.01 | Aug 22, 2022 | The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute… | ||
| CVE-2022-30852 | Med | 0.28 | 4.3 | 0.01 | Jul 8, 2022 | Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). | ||
| CVE-2022-30760 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2022 | An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to… | ||
| CVE-2022-29627 | Med | 0.28 | 4.3 | 0.01 | Jun 2, 2022 | An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers. | ||
| CVE-2022-1425 | Med | 0.28 | 4.3 | 0.01 | May 16, 2022 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read messages for any other… | ||
| CVE-2021-24800 | Med | 0.28 | 4.3 | 0.01 | Apr 25, 2022 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments. | ||
| CVE-2022-27108 | Med | 0.28 | 4.3 | 0.01 | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account. | ||
| CVE-2022-0442 | Med | 0.28 | 4.3 | 0.01 | Mar 7, 2022 | The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar. | ||
| CVE-2022-0639 | Med | 0.28 | 5.3 | 0.02 | Feb 17, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. | ||
| CVE-2022-0512 | Med | 0.28 | 5.3 | 0.02 | Feb 14, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. | ||
| CVE-2021-44836 | Med | 0.28 | 4.3 | 0.01 | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened. | ||
| CVE-2021-39934 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. | ||
| CVE-2021-39916 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2021 | Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from… | ||
| CVE-2021-39889 | Med | 0.28 | 4.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch. | ||
| CVE-2021-33981 | Med | 0.28 | 4.3 | 0.01 | Sep 8, 2021 | An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and images of their hunting/fishing licenses. | ||
| CVE-2021-37215 | Med | 0.28 | 4.3 | 0.01 | Aug 9, 2021 | The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s… |
- risk 0.28cvss 4.3epss 0.00
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
- risk 0.28cvss 4.3epss 0.01
The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.
- risk 0.28cvss 4.3epss 0.01
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
- risk 0.28cvss 5.3epss 0.02
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
- risk 0.28cvss 4.3epss 0.01
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute…
- risk 0.28cvss 4.3epss 0.01
Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
- risk 0.28cvss 4.3epss 0.01
An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to…
- risk 0.28cvss 4.3epss 0.01
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.
- risk 0.28cvss 4.3epss 0.01
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read messages for any other…
- risk 0.28cvss 4.3epss 0.01
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
- risk 0.28cvss 4.3epss 0.01
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
- risk 0.28cvss 4.3epss 0.01
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
- risk 0.28cvss 5.3epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
- risk 0.28cvss 5.3epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.
- risk 0.28cvss 4.3epss 0.01
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
- risk 0.28cvss 4.3epss 0.01
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from…
- risk 0.28cvss 4.3epss 0.01
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
- risk 0.28cvss 4.3epss 0.01
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and images of their hunting/fishing licenses.
- risk 0.28cvss 4.3epss 0.01
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s…