CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,085 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 5 of 42
- CVE-2021-37628HIGHCVSS 7.5EG 7.52021-09-07
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able t…
- CVE-2021-37630MEDIUMCVSS 6.5EG 6.52021-09-07
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private …
- CVE-2021-37631MEDIUMCVSS 6.5EG 6.52021-09-07
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle.…
- CVE-2021-37709MEDIUMCVSS 6.5EG 6.52021-08-16
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for …
- CVE-2021-37777HIGHCVSS 7.5EG 7.52021-10-04
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive inf…
- CVE-2021-3813MEDIUMCVSS 6.5EG 6.52022-02-09
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
- CVE-2021-38362MEDIUMCVSS 6.5EG 6.52022-03-30
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
- CVE-2021-3852HIGHCVSS 7.5EG 7.52022-01-12
growi is vulnerable to Authorization Bypass Through User-Controlled Key
- CVE-2021-38624MEDIUMCVSS 6.5EG 6.52021-09-15
Windows Key Storage Provider Security Feature Bypass Vulnerability
- CVE-2021-39225HIGHCVSS 8.1EG 8.12021-10-25
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the …
- CVE-2021-3964MEDIUMCVSS 5.9EG 5.92021-12-01
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
- CVE-2021-3965HIGHCVSS 7.5EG 7.52022-01-14
Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.
- CVE-2021-39889MEDIUMCVSS 4.3EG 4.32021-10-05
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branc…
- CVE-2021-3991MEDIUMCVSS 4.3EG 4.32024-11-15
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing …
- CVE-2021-39916MEDIUMCVSS 4.3EG 4.32021-12-13
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 b…
- CVE-2021-3992MEDIUMCVSS 6.5EG 6.52021-12-01
kimai2 is vulnerable to Improper Access Control
- CVE-2021-39934MEDIUMCVSS 4.3EG 4.32021-12-13
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.…
- CVE-2021-40352MEDIUMCVSS 6.5EG 6.52021-09-01
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
- CVE-2021-40355HIGHCVSS 8.8EG 8.82021-09-14
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The affected applicat…
- CVE-2021-40579MEDIUMCVSS 6.5EG 6.52021-12-28
https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. The impact is: gain privileges (remote).
- CVE-2021-41111MEDIUMCVSS 6.4EG 6.42022-02-28
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal We…
- CVE-2021-41120HIGHCVSS 7.5EG 7.52021-10-05
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy…
- CVE-2021-41129HIGHCVSS 8.1EG 8.12021-10-06
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value no…
- CVE-2021-41298HIGHCVSS 8.8EG 8.82021-09-30
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privile…
- CVE-2021-41301CRITICALCVSS 9.8EG 9.82021-09-30
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information an…
- CVE-2021-41305HIGHCVSS 7.5EG 7.52021-10-26
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in S…
- CVE-2021-41306HIGHCVSS 7.5EG 7.52021-10-26
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The af…
- CVE-2021-41307HIGHCVSS 7.5EG 7.52021-10-26
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie C…
- CVE-2021-4142MEDIUMCVSS 5.5EG 5.52022-08-24
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
- CVE-2021-41608HIGHCVSS 7.5EG 7.52022-01-28
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in s…
- CVE-2021-41847HIGHCVSS 8.8EG 8.82021-10-01
An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to a specific zone can send modified HTTP GET and POST requests, allowing them to view user …
- CVE-2021-4226CRITICALCVSS 9.8EG 9.82022-12-15
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
- CVE-2021-43820HIGHCVSS 7.4EG 7.42021-12-14
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sy…
- CVE-2021-43828HIGHCVSS 7.5EG 7.52021-12-14
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/…
- CVE-2021-43957HIGHCVSS 7.5EG 7.52022-03-16
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of …
- CVE-2021-44160HIGHCVSS 7.3EG 7.32021-12-29
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform…
- CVE-2021-44836MEDIUMCVSS 4.3EG 4.32022-01-18
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the …
- CVE-2021-44949CRITICALCVSS 9.8EG 9.82021-12-14
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
- CVE-2021-45428CRITICALCVSS 9.8EG 9.82022-01-03
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
- CVE-2021-46249MEDIUMCVSS 6.5EG 6.52022-02-15
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their ow…
- CVE-2021-46416HIGHCVSS 8.1EG 8.12022-04-07
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
- CVE-2021-47721HIGHCVSS 8.8EG 8.82025-12-23
Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source…
- CVE-2022-0266MEDIUMCVSS 6.6EG 6.62022-01-19
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
- CVE-2022-0442MEDIUMCVSS 4.3EG 4.32022-03-07
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
- CVE-2022-0512MEDIUMCVSS 5.3EG 5.32022-02-14
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
- CVE-2022-0613MEDIUMCVSS 6.5EG 6.52022-02-16
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
- CVE-2022-0624HIGHCVSS 7.3EG 7.32022-06-28
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
- CVE-2022-0639MEDIUMCVSS 5.3EG 5.32022-02-17
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
- CVE-2022-0686CRITICALCVSS 9.1EG 9.12022-02-20
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
- CVE-2022-0691CRITICALCVSS 9.8EG 9.82022-02-21
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →