CWE-639
1,728 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVEs (1,728)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization. |
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request. |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Sep 30, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a misuse of the general enquiry web service. |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
1Boldworkplanner 1Bold Workplanner Oct 8, 2025 Sep 30, 2025 7.1 HIGH· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to...Show more |
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with...Show more |
A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pessoa/validarCpf of the component CPF Handler. Executing a manipulation...Show more |
Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse.
This issue affects AHE Mobile: from 1.9.7 before 1.9.9. |
danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/server/middleware/roles/access.js` uses `permissions.some()` to validat...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Sep 22, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through upd...Show more |
Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <...Show more |
Authorization Bypass Through User-Controlled Key vulnerability in Alex Content Mask content-mask allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Mask: from n/a through <...Show more |
Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists upcoming-events-lists allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Upcomi...Show more |