← Back
CWE-639

1,734 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (1,734)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated attackers can rename "rooms" of arbitrary users.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An unauthenticated attacker can hijack other users' devices and potentially control them.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An attacker can export other users' plant information.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An authenticated attacker can obtain any plant name by knowing the plant ID.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
1Growatt
1Cloud Portal
Nov 14, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can obtain a user's plant list by knowing the username.
1Growatt
1Cloud Portal
Nov 12, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
1Growatt
1Cloud Portal
Nov 12, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
1Growatt
1Cloud Portal
Nov 12, 2025
Apr 15, 2025
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
An attacker can change registered email addresses of other users and take over arbitrary accounts.
1Growatt
1Cloud Portal
Nov 12, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
1Growatt
1Cloud Portal
Nov 12, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
1Growatt
1Cloud Portal
Nov 12, 2025
Apr 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
-
-
Apr 15, 2025
Apr 15, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" e...Show more
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint.Show less
-
-
Apr 15, 2025
Apr 15, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoi...Show more
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint.Show less
1Tutorials Website
1Employee Management System
Jun 5, 2025
Apr 13, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/update-user.php. The manipulation of the argument ID lead...Show more
A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/update-user.php. The manipulation of the argument ID leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Tutorials Website
1Employee Management System
Jun 5, 2025
Apr 13, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete-user.php. The manipulation of the a...Show more
A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete-user.php. The manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less