CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 17 of 43
- CVE-2024-4817MEDIUMCVSS 6.3EG 6.32024-05-14
A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulat…
- CVE-2024-4819MEDIUMCVSS 4.3EG 4.32024-05-14
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file admin_class.php. The manipulation of the argument type with the input 1 leads t…
- CVE-2024-48217HIGHCVSS 8.8EG 8.82024-11-01
An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.
- CVE-2024-4843MEDIUMCVSS 4.3EG 4.32024-05-16
ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.
- CVE-2024-4873MEDIUMCVSS 4.3EG 4.32024-06-19
The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it…
- CVE-2024-4874MEDIUMCVSS 4.3EG 4.32024-06-22
The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.8 via the postId parameter due to missing validation on a user controlled key. This makes it possible for a…
- CVE-2024-4886MEDIUMCVSS 4.3EG 4.32024-06-05
The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request
- CVE-2024-48899MEDIUMCVSS 4.3EG 4.32024-11-20
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
- CVE-2024-49388CRITICALCVSS 9.1EG 9.12024-10-15
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
- CVE-2024-50395HIGHCVSS 8.8EG 8.82024-11-22
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnera…
- CVE-2024-50483CRITICALCVSS 9.8EG 9.82024-10-28
Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.
- CVE-2024-50651MEDIUMCVSS 6.5EG 6.52024-11-15
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
- CVE-2024-50685CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.
- CVE-2024-50686CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.
- CVE-2024-50687CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model.
- CVE-2024-50689CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.
- CVE-2024-50693CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
- CVE-2024-51066HIGHCVSS 7.5EG 7.52024-10-31
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
- CVE-2024-5128CRITICALCVSS 8.8EG 9.42024-06-06
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or datase…
- CVE-2024-5130HIGHCVSS 7.5EG 7.52024-06-06
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the da…
- CVE-2024-5131HIGHCVSS 6.5EG 7.52024-06-06
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any prompts in any projects by supplying a specific promp…
- CVE-2024-51559MEDIUMCVSS 6.5EG 6.52024-11-04
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and…
- CVE-2024-5166MEDIUMCVSS 6.5EG 6.52024-05-22
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
- CVE-2024-52294MEDIUMCVSS 4.3EG 4.32024-12-30
Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR) vulnerability in the update_subscription endpoint allows any authenticated user to manipulate other users' Stripe sub…
- CVE-2024-52313MEDIUMCVSS 4.3EG 4.32024-11-09
An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnviro…
- CVE-2024-52507LOWCVSS 3.5EG 3.52024-11-15
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended t…
- CVE-2024-52511MEDIUMCVSS 6.3EG 6.32024-11-15
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Next…
- CVE-2024-5258MEDIUMCVSS 4.4EG 4.42024-05-23
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization…
- CVE-2024-52601MEDIUMCVSS 6.5EG 6.52025-05-14
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions …
- CVE-2024-53406HIGHCVSS 8.8EG 8.82025-03-13
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to ex…
- CVE-2024-53617MEDIUMCVSS 4.8EG 4.82024-12-02
A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.
- CVE-2024-5438MEDIUMCVSS 4.3EG 4.32024-06-07
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user…
- CVE-2024-55186MEDIUMCVSS 4.3EG 4.32024-12-20
An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notificati…
- CVE-2024-55231MEDIUMCVSS 4.3EG 4.32024-12-18
An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensi…
- CVE-2024-55471MEDIUMCVSS 6.5EG 6.52024-12-20
Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.
- CVE-2024-55506HIGHCVSS 8.8EG 8.82024-12-18
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.
- CVE-2024-56143HIGHCVSS 8.2EG 8.22025-10-16
Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can acces…
- CVE-2024-5619CRITICALCVSS 9.6EG 9.62024-07-18
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apinizer Management Console: b…
- CVE-2024-5639MEDIUMCVSS 4.3EG 4.32024-06-21
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key…
- CVE-2024-5942MEDIUMCVSS 4.3EG 4.32024-06-29
The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it pos…
- CVE-2024-5977MEDIUMCVSS 5.4EG 5.42024-07-19
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a use…
- CVE-2024-6087MEDIUMCVSS 6.5EG 6.52024-09-13
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invite user' functionality to obtain valid JW…
- CVE-2024-6357MEDIUMCVSS 6.3EG 6.32024-08-06
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
- CVE-2024-6410MEDIUMCVSS 4.3EG 4.32024-07-10
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a …
- CVE-2024-6534MEDIUMCVSS 4.3EG 4.32024-08-15
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' reque…
- CVE-2024-6685LOWCVSS 3.1EG 3.12024-09-16
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.
- CVE-2024-7041MEDIUMCVSS 6.5EG 6.52024-10-09
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is f…
- CVE-2024-7437MEDIUMCVSS 5.4EG 5.42024-08-03
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipul…
- CVE-2024-7438MEDIUMCVSS 4.3EG 4.32024-08-03
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Al…
- CVE-2024-7473HIGHCVSS 6.5EG 7.52024-10-29
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' paramete…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →