CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 10 of 43
- CVE-2023-32078HIGHCVSS 7.5EG 7.52023-08-24
Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in the user update function. By specifying another user's username, it was possible to update…
- CVE-2023-32189MEDIUMCVSS 5.9EG 5.92024-10-16
Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
- CVE-2023-3219MEDIUMCVSS 5.3EG 5.32023-07-10
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected post…
- CVE-2023-32310HIGHCVSS 8.1EG 8.12023-06-01
DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting ano…
- CVE-2023-32352MEDIUMCVSS 5.5EG 5.52023-06-23
A logic issue was addressed with improved checks. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may bypass Gatekeeper checks.
- CVE-2023-32669MEDIUMCVSS 5.4EG 5.42023-10-03
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (…
- CVE-2023-32747MEDIUMCVSS 5.4EG 5.42023-12-21
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.
- CVE-2023-32799MEDIUMCVSS 6.5EG 6.52023-12-21
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.
- CVE-2023-3285HIGHCVSS 7.7EG 7.72024-07-09
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.
- CVE-2023-3286HIGHCVSS 7.7EG 7.72024-07-09
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.
- CVE-2023-3287CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation.
- CVE-2023-3288HIGHCVSS 8.5EG 8.52024-07-09
A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.
- CVE-2023-3289HIGHCVSS 7.7EG 7.72024-07-09
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
- CVE-2023-3290MEDIUMCVSS 5.0EG 5.02024-07-09
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
- CVE-2023-33706MEDIUMCVSS 6.5EG 6.52023-11-24
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
- CVE-2023-33956MEDIUMCVSS 4.3EG 4.32023-06-05
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direct object reference (IDOR) vulnerability present in the application's URL parameter. This v…
- CVE-2023-34000HIGHCVSS 7.5EG 7.52023-06-14
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
- CVE-2023-3525HIGHCVSS 7.5EG 7.52023-07-12
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attack…
- CVE-2023-35876HIGHCVSS 8.1EG 8.12023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.
- CVE-2023-35914HIGHCVSS 7.5EG 7.52023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
- CVE-2023-35916HIGHCVSS 7.5EG 7.52023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from…
- CVE-2023-3601MEDIUMCVSS 4.3EG 4.32023-08-14
The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
- CVE-2023-36235MEDIUMCVSS 6.5EG 6.52024-01-17
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
- CVE-2023-36238MEDIUMCVSS 6.5EG 6.52024-03-13
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
- CVE-2023-36331HIGHCVSS 8.2EG 8.22026-01-12
Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.
- CVE-2023-36483MEDIUMCVSS 6.5EG 6.52024-03-16
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data inc…
- CVE-2023-36520MEDIUMCVSS 5.4EG 5.42023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.
- CVE-2023-3700MEDIUMCVSS 6.3EG 6.32023-07-17
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- CVE-2023-3706MEDIUMCVSS 4.3EG 4.32023-10-16
The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft …
- CVE-2023-3707MEDIUMCVSS 4.3EG 4.32023-10-16
The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as dr…
- CVE-2023-37242CRITICALCVSS 9.8EG 9.82023-07-06
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilitie…
- CVE-2023-37543HIGHCVSS 7.5EG 7.52023-08-10
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
- CVE-2023-37871HIGHCVSS 8.2EG 8.22023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
- CVE-2023-38047HIGHCVSS 8.5EG 8.52024-07-09
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38048CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38049CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipula…
- CVE-2023-38050CRITICALCVSS 9.1EG 9.12024-07-09
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38051CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38052CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38053CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38054CRITICALCVSS 9.9EG 9.92024-07-09
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38055CRITICALCVSS 9.6EG 9.62024-07-09
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
- CVE-2023-38201MEDIUMCVSS 6.5EG 6.52023-08-25
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if t…
- CVE-2023-38257HIGHCVSS 7.5EG 7.52023-07-18
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
- CVE-2023-38513MEDIUMCVSS 5.4EG 5.42023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.
- CVE-2023-3869MEDIUMCVSS 5.3EG 5.32023-10-20
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated att…
- CVE-2023-38872LOWCVSS 3.7EG 3.72023-09-28
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of …
- CVE-2023-38884HIGHCVSS 7.5EG 7.52023-11-20
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filenam…
- CVE-2023-38965CRITICALCVSS 9.8EG 9.82023-11-03
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
- CVE-2023-3998MEDIUMCVSS 5.3EG 5.32023-10-20
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attacker…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →