CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 15 of 43
- CVE-2024-2472CRITICALCVSS 9.1EG 9.12024-06-14
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9…
- CVE-2024-25270MEDIUMCVSS 4.3EG 4.32024-09-12
An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
- CVE-2024-2538MEDIUMCVSS 5.4EG 5.42024-03-20
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possibl…
- CVE-2024-2543MEDIUMCVSS 4.3EG 4.32024-04-09
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unaut…
- CVE-2024-2574HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-task.php. The manipulation of the argument task_id leads t…
- CVE-2024-2575HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality of the file /task-details.php. The manipulation of the argument t…
- CVE-2024-2576HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorizatio…
- CVE-2024-2577HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to a…
- CVE-2024-25983LOWCVSS 3.5EG 3.52024-02-19
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
- CVE-2024-27113CRITICALCVSS 9.8EG 9.82024-09-11
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlyin…
- CVE-2024-27302CRITICALCVSS 9.1EG 9.12024-03-06
go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allowed in CORS policy. However, the `isOriginAllowed` uses `strings.HasSuffix` to check the o…
- CVE-2024-27630HIGHCVSS 7.5EG 7.52024-04-08
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
- CVE-2024-27730CRITICALCVSS 9.8EG 9.82024-08-15
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.
- CVE-2024-28320HIGHCVSS 7.6EG 7.62024-04-29
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.
- CVE-2024-29020MEDIUMCVSS 4.6EG 4.62024-03-29
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the playbook_id of another us…
- CVE-2024-29024MEDIUMCVSS 4.6EG 4.62024-03-29
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulati…
- CVE-2024-29181LOWCVSS 2.3EG 2.32024-06-12
Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role c…
- CVE-2024-29194HIGHCVSS 8.3EG 8.32024-03-24
OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_master_admin key, stored in the local storag…
- CVE-2024-3035MEDIUMCVSS 6.8EG 6.82024-08-08
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.
- CVE-2024-30507LOWCVSS 2.7EG 2.72024-03-29
Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.
- CVE-2024-30513MEDIUMCVSS 6.5EG 6.52024-03-29
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.
- CVE-2024-30543MEDIUMCVSS 6.5EG 6.52024-03-31
Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18.
- CVE-2024-31095CRITICALCVSS 5.3EG 9.12024-03-31
Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0.
- CVE-2024-31291MEDIUMCVSS 4.3EG 4.32024-04-07
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.
- CVE-2024-31296MEDIUMCVSS 4.3EG 4.32024-04-07
Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.
- CVE-2024-3139MEDIUMCVSS 5.4EG 5.42024-04-01
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the…
- CVE-2024-31815CRITICALCVSS 9.1EG 9.12024-04-08
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
- CVE-2024-31898MEDIUMCVSS 5.4EG 5.42024-06-30
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.
- CVE-2024-32045MEDIUMCVSS 5.9EG 5.92024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channe…
- CVE-2024-32166HIGHCVSS 8.8EG 8.82024-04-19
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
- CVE-2024-32604MEDIUMCVSS 4.3EG 4.32024-04-18
Authorization Bypass Through User-Controlled Key vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
- CVE-2024-32683MEDIUMCVSS 5.3EG 5.32024-04-19
Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
- CVE-2024-32772MEDIUMCVSS 4.3EG 4.32024-04-24
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
- CVE-2024-32808MEDIUMCVSS 5.4EG 5.42024-04-24
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
- CVE-2024-32823MEDIUMCVSS 5.3EG 5.32024-04-24
Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.4.
- CVE-2024-3305HIGHCVSS 7.5EG 7.52024-09-12
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.
- CVE-2024-3306HIGHCVSS 7.5EG 7.52024-09-12
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for And…
- CVE-2024-33373MEDIUMCVSS 6.3EG 6.32024-06-14
An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can allow attackers to access the router via a brute-force atta…
- CVE-2024-33383HIGHCVSS 7.5EG 7.52024-04-30
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
- CVE-2024-33542MEDIUMCVSS 4.3EG 4.32024-04-29
Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly Slider: from n/a through 1.4.5.
- CVE-2024-33668CRITICALCVSS 9.1EG 9.12024-04-26
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no ac…
- CVE-2024-33818HIGHCVSS 7.5EG 7.52024-05-14
Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.
- CVE-2024-34383MEDIUMCVSS 5.3EG 5.32024-05-06
Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7.1.
- CVE-2024-34457MEDIUMCVSS 6.5EG 6.52024-07-22
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should …
- CVE-2024-34520HIGHCVSS 8.8EG 8.82025-02-12
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing th…
- CVE-2024-36399HIGHCVSS 8.2EG 8.22024-06-06
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL pa…
- CVE-2024-37277HIGHCVSS 7.5EG 7.52024-11-01
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
- CVE-2024-37889MEDIUMCVSS 6.5EG 6.52024-06-14
MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerab…
- CVE-2024-38446MEDIUMCVSS 6.5EG 6.52024-07-17
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in …
- CVE-2024-38447HIGHCVSS 8.1EG 8.12024-07-17
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →