VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 83 of 115
  • CVE-2021-37213MedAug 9, 2021
    risk 0.28cvss 4.3epss 0.01

    The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.

  • CVE-2021-35337MedJul 1, 2021
    risk 0.28cvss 4.3epss 0.01

    Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.

  • CVE-2021-31927MedJun 10, 2021
    risk 0.28cvss 4.3epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.

  • CVE-2020-6641MedJun 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.

  • CVE-2020-26679MedMay 26, 2021
    risk 0.28cvss 4.3epss 0.01

    vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made…

  • CVE-2020-36231MedFeb 2, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0…

  • CVE-2020-26171MedDec 18, 2020
    risk 0.28cvss 4.3epss 0.01

    In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

  • CVE-2020-13357MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

  • CVE-2020-27663MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).

  • CVE-2020-27662MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).

  • CVE-2020-8235MedOct 5, 2020
    risk 0.28cvss 4.3epss 0.01

    Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

  • CVE-2020-12643MedAug 31, 2020
    risk 0.28cvss 4.3epss 0.01

    OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.

  • CVE-2020-14174MedJul 13, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from…

  • CVE-2020-5743MedMay 7, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.

  • CVE-2020-11659MedApr 15, 2020
    risk 0.28cvss 4.3epss 0.01

    CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.

  • CVE-2020-11585MedApr 6, 2020
    risk 0.28cvss 4.3epss 0.01

    There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by…

  • CVE-2020-9468MedMar 26, 2020
    risk 0.28cvss 4.3epss 0.01

    The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.

  • CVE-2019-18626MedMar 25, 2020
    risk 0.28cvss 4.3epss 0.01

    Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax…

  • CVE-2019-5466MedJan 28, 2020
    risk 0.28cvss 4.3epss 0.01

    An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

  • CVE-2019-19616MedDec 6, 2019
    risk 0.28cvss 4.3epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the…