CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,110 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 6 of 43
- CVE-2022-0731MEDIUMCVSS 6.5EG 6.52022-02-23
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
- CVE-2022-0732HIGHCVSS 7.5EG 7.52022-02-24
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
- CVE-2022-1165CRITICALCVSS 9.1EG 9.12022-04-04
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking…
- CVE-2022-1245CRITICALCVSS 9.8EG 9.82022-07-08
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target…
- CVE-2022-1352MEDIUMCVSS 5.3EG 5.32022-05-11
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an AP…
- CVE-2022-1425MEDIUMCVSS 4.3EG 4.32022-05-16
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being …
- CVE-2022-1459HIGHCVSS 8.3EG 8.32022-04-25
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
- CVE-2022-1461MEDIUMCVSS 6.5EG 6.52022-04-25
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- CVE-2022-1579HIGHCVSS 7.5EG 7.52022-11-21
The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.
- CVE-2022-1580MEDIUMCVSS 4.3EG 4.32022-09-19
The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypas…
- CVE-2022-1581MEDIUMCVSS 5.3EG 5.32022-11-21
The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
- CVE-2022-1600MEDIUMCVSS 5.3EG 5.32022-08-01
The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
- CVE-2022-1613MEDIUMCVSS 5.3EG 5.32022-09-26
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.
- CVE-2022-1614HIGHCVSS 7.5EG 7.52022-06-20
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
- CVE-2022-1762HIGHCVSS 7.5EG 7.52022-06-13
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
- CVE-2022-1810MEDIUMCVSS 4.3EG 4.32022-05-23
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.
- CVE-2022-1881MEDIUMCVSS 5.3EG 5.32022-07-15
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impa…
- CVE-2022-1949HIGHCVSS 7.5EG 7.52022-06-02
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any …
- CVE-2022-1996CRITICALCVSS 9.1EG 9.12022-06-08
Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
- CVE-2022-2034MEDIUMCVSS 5.3EG 5.32022-08-29
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
- CVE-2022-2080MEDIUMCVSS 4.3EG 4.32022-08-29
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR a…
- CVE-2022-21713MEDIUMCVSS 4.3EG 4.32022-02-08
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view …
- CVE-2022-2193HIGHCVSS 7.5EG 8.82022-07-19
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue aff…
- CVE-2022-2198MEDIUMCVSS 4.3EG 4.32022-08-22
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the m…
- CVE-2022-22190HIGHCVSS 7.4EG 7.52022-04-14
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration i…
- CVE-2022-22331HIGHCVSS 7.1EG 7.12022-04-01
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.
- CVE-2022-2243MEDIUMCVSS 5.0EG 5.02022-07-01
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
- CVE-2022-22828HIGHCVSS 7.5EG 7.52022-01-27
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
- CVE-2022-22832CRITICALCVSS 9.8EG 9.82022-02-06
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
- CVE-2022-23061MEDIUMCVSS 6.5EG 6.52022-05-01
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
- CVE-2022-2312MEDIUMCVSS 5.4EG 5.42022-08-22
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Fur…
- CVE-2022-23173MEDIUMCVSS 5.5EG 6.32022-07-06
this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the att…
- CVE-2022-2367HIGHCVSS 7.5EG 7.52022-08-08
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation
- CVE-2022-23856MEDIUMCVSS 5.3EG 5.32022-01-24
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.
- CVE-2022-24187HIGHCVSS 7.5EG 7.52022-11-28
The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and device_id values can be enumerated by incrementing or decrement…
- CVE-2022-24400HIGHCVSS 7.5EG 7.52023-10-19
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.
- CVE-2022-24401HIGHCVSS 8.8EG 8.82023-10-19
Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthentica…
- CVE-2022-24979MEDIUMCVSS 5.3EG 5.32022-02-19
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content e…
- CVE-2022-2499MEDIUMCVSS 3.5EG 4.32022-08-05
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure dir…
- CVE-2022-25336MEDIUMCVSS 5.3EG 5.32022-02-18
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
- CVE-2022-2535MEDIUMCVSS 5.3EG 5.32022-08-15
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post t…
- CVE-2022-25471HIGHCVSS 8.1EG 8.12022-03-03
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.
- CVE-2022-26254MEDIUMCVSS 5.3EG 5.32022-03-27
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.
- CVE-2022-26665HIGHCVSS 7.5EG 7.52022-04-18
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
- CVE-2022-27108MEDIUMCVSS 4.3EG 4.32022-04-06
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
- CVE-2022-27247MEDIUMCVSS 5.3EG 5.32022-05-13
onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Re…
- CVE-2022-2730MEDIUMCVSS 6.5EG 6.52022-08-09
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- CVE-2022-2808HIGHCVSS 8.8EG 8.82022-12-02
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11.
- CVE-2022-2824HIGHCVSS 8.8EG 8.82022-08-15
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- CVE-2022-2828MEDIUMCVSS 6.5EG 6.52022-10-13
In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →