CWE-639
2,515 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVEs (2,515)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in all versions up to, and including, 1.4.0. This is due...Show more |
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to...Show more |
Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ERIC). This vulnerability allows an attacker to access or modify unauthor...Show more |
Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure.
This issue affects Logo Cloud: before 0.67. |
A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performi...Show more |
Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. Assist allows Excavation, Authentication Bypass. This issue affects Assi...Show more |
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information a...Show more |
IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization. |
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Sep 30, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a misuse of the general enquiry web service. |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Jun 17, 2026 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with...Show more |