CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,113 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 7 of 43
- CVE-2022-2877MEDIUMCVSS 5.3EG 5.32022-09-16
The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
- CVE-2022-28986HIGHCVSS 7.5EG 7.52022-05-10
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone num…
- CVE-2022-29008HIGHCVSS 6.5EG 7.52022-05-11
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
- CVE-2022-2913MEDIUMCVSS 4.3EG 4.32022-09-16
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
- CVE-2022-29159MEDIUMCVSS 5.0EG 5.02022-05-20
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextclou…
- CVE-2022-29287MEDIUMCVSS 4.9EG 4.92022-04-16
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like G…
- CVE-2022-29434MEDIUMCVSS 6.3EG 6.32022-05-20
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
- CVE-2022-29627MEDIUMCVSS 4.3EG 4.32022-06-02
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.
- CVE-2022-3019HIGHCVSS 8.8EG 8.82022-08-29
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long tim…
- CVE-2022-30495CRITICALCVSS 9.8EG 9.82022-05-26
In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)
- CVE-2022-30760MEDIUMCVSS 4.3EG 4.32022-06-09
An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID…
- CVE-2022-30852MEDIUMCVSS 4.3EG 4.32022-07-08
Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
- CVE-2022-31027MEDIUMCVSS 4.2EG 4.22022-06-09
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub o…
- CVE-2022-31131MEDIUMCVSS 5.4EG 5.42022-07-06
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have b…
- CVE-2022-31295HIGHCVSS 7.5EG 7.52022-06-16
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
- CVE-2022-31683MEDIUMCVSS 5.4EG 5.42022-12-19
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belon…
- CVE-2022-31692CRITICALCVSS 9.8EG 9.82022-10-31
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: …
- CVE-2022-31883HIGHCVSS 8.8EG 8.82022-06-28
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
- CVE-2022-32277MEDIUMCVSS 5.3EG 5.32022-09-06
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and th…
- CVE-2022-3282MEDIUMCVSS 4.3EG 4.32022-10-17
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the…
- CVE-2022-33077HIGHCVSS 7.5EG 7.52022-10-19
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
- CVE-2022-3331MEDIUMCVSS 3.5EG 4.32022-10-17
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure di…
- CVE-2022-3343LOWCVSS 3.5EG 3.52023-01-09
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing…
- CVE-2022-33944MEDIUMCVSS 6.5EG 6.52022-07-20
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs.
- CVE-2022-3413MEDIUMCVSS 4.3EG 4.32022-11-10
Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or M…
- CVE-2022-34138HIGHCVSS 7.5EG 7.52023-02-03
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information.
- CVE-2022-34150HIGHCVSS 7.1EG 7.12022-07-20
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
- CVE-2022-3459MEDIUMCVSS 5.3EG 5.32024-09-14
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. Thi…
- CVE-2022-34621MEDIUMCVSS 6.5EG 6.52022-08-19
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
- CVE-2022-34769MEDIUMCVSS 6.3EG 6.32022-08-05
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. Howe…
- CVE-2022-34770HIGHCVSS 4.6EG 7.52022-08-22
Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, alcohol consumption and smoking habits. Each…
- CVE-2022-34775HIGHCVSS 6.3EG 7.52022-08-22
Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This can be used to query the http://tgm-api.tabit.cloud/rsv/ma…
- CVE-2022-3511MEDIUMCVSS 6.5EG 6.52022-11-28
The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported …
- CVE-2022-3589HIGHCVSS 8.1EG 8.12022-11-21
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a …
- CVE-2022-36202CRITICALCVSS 9.8EG 9.82022-08-31
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
- CVE-2022-36247CRITICALCVSS 9.1EG 9.12023-05-30
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
- CVE-2022-36284MEDIUMCVSS 6.4EG 6.52022-08-05
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the e…
- CVE-2022-36539HIGHCVSS 7.5EG 7.52022-09-07
WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.
- CVE-2022-36966MEDIUMCVSS 5.4EG 5.42022-10-20
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
- CVE-2022-3794MEDIUMCVSS 5.4EG 5.42022-12-22
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and m…
- CVE-2022-3805HIGHCVSS 8.6EG 8.62022-12-22
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obta…
- CVE-2022-3846HIGHCVSS 7.5EG 7.52022-12-05
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.
- CVE-2022-3876MEDIUMCVSS 4.3EG 6.52022-12-19
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of…
- CVE-2022-38765MEDIUMCVSS 6.5EG 6.52022-12-09
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
- CVE-2022-38789CRITICALCVSS 9.1EG 9.12022-09-15
An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.
- CVE-2022-3891MEDIUMCVSS 5.3EG 5.32023-02-13
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary pos…
- CVE-2022-39018HIGHCVSS 8.2EG 8.22022-10-31
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
- CVE-2022-3930MEDIUMCVSS 6.5EG 6.52022-12-12
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
- CVE-2022-39945MEDIUMCVSS 5.4EG 6.52022-11-02
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other…
- CVE-2022-3995MEDIUMCVSS 4.3EG 4.32022-11-29
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. Th…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →