CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 19 of 60
- CVE-2023-38257HIGHCVSS 7.5EG 7.52023-07-18
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
- CVE-2023-3525HIGHCVSS 7.5EG 7.52023-07-12
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attack…
- CVE-2023-3133HIGHCVSS 7.5EG 7.52023-07-04
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
- CVE-2023-34000HIGHCVSS 7.5EG 7.52023-06-14
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
- CVE-2018-17455HIGHCVSS 7.5EG 7.52023-04-15
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure di…
- CVE-2018-17449HIGHCVSS 7.5EG 7.52023-04-15
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API…
- CVE-2023-25403HIGHCVSS 7.5EG 7.52023-03-03
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username t…
- CVE-2022-4550HIGHCVSS 7.5EG 7.52023-02-27
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
- CVE-2022-34138HIGHCVSS 7.5EG 7.52023-02-03
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information.
- CVE-2022-4794HIGHCVSS 7.5EG 7.52023-01-30
The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
- CVE-2022-40319HIGHCVSS 7.5EG 7.52023-01-17
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.
- CVE-2022-3846HIGHCVSS 7.5EG 7.52022-12-05
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.
- CVE-2022-43326HIGHCVSS 7.5EG 7.52022-11-29
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.
- CVE-2022-24187HIGHCVSS 7.5EG 7.52022-11-28
The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and device_id values can be enumerated by incrementing or decrement…
- CVE-2022-1579HIGHCVSS 7.5EG 7.52022-11-21
The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.
- CVE-2022-33077HIGHCVSS 7.5EG 7.52022-10-19
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
- CVE-2022-41479HIGHCVSS 7.5EG 7.52022-10-18
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) v…
- CVE-2022-36539HIGHCVSS 7.5EG 7.52022-09-07
WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.
- CVE-2022-2367HIGHCVSS 7.5EG 7.52022-08-08
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation
- CVE-2021-24655HIGHCVSS 7.5EG 7.52022-07-17
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user k…
- CVE-2022-1614HIGHCVSS 7.5EG 7.52022-06-20
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
- CVE-2022-31295HIGHCVSS 7.5EG 7.52022-06-16
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
- CVE-2022-1762HIGHCVSS 7.5EG 7.52022-06-13
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
- CVE-2022-1949HIGHCVSS 7.5EG 7.52022-06-02
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any …
- CVE-2022-28986HIGHCVSS 7.5EG 7.52022-05-10
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone num…
- CVE-2022-26665HIGHCVSS 7.5EG 7.52022-04-18
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
- CVE-2021-43957HIGHCVSS 7.5EG 7.52022-03-16
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of …
- CVE-2022-0732HIGHCVSS 7.5EG 7.52022-02-24
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
- CVE-2021-41608HIGHCVSS 7.5EG 7.52022-01-28
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in s…
- CVE-2022-22828HIGHCVSS 7.5EG 7.52022-01-27
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
- CVE-2021-3965HIGHCVSS 7.5EG 7.52022-01-14
Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.
- CVE-2021-3852HIGHCVSS 7.5EG 7.52022-01-12
growi is vulnerable to Authorization Bypass Through User-Controlled Key
- CVE-2021-43828HIGHCVSS 7.5EG 7.52021-12-14
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/…
- CVE-2021-22967HIGHCVSS 7.5EG 7.52021-11-19
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files …
- CVE-2021-22951HIGHCVSS 7.5EG 7.52021-11-19
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file…
- CVE-2021-41307HIGHCVSS 7.5EG 7.52021-10-26
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie C…
- CVE-2021-41306HIGHCVSS 7.5EG 7.52021-10-26
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The af…
- CVE-2021-41305HIGHCVSS 7.5EG 7.52021-10-26
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in S…
- CVE-2021-36389HIGHCVSS 7.5EG 7.52021-10-14
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".
- CVE-2021-36388HIGHCVSS 7.5EG 7.52021-10-14
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".
- CVE-2021-41120HIGHCVSS 7.5EG 7.52021-10-05
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy…
- CVE-2021-37777HIGHCVSS 7.5EG 7.52021-10-04
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive inf…
- CVE-2021-37628HIGHCVSS 7.5EG 7.52021-09-07
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able t…
- CVE-2021-24562HIGHCVSS 7.5EG 7.52021-08-23
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
- CVE-2020-23449HIGHCVSS 7.5EG 7.52021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
- CVE-2020-35849HIGHCVSS 7.5EG 7.52020-12-30
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potent…
- CVE-2020-20183HIGHCVSS 7.5EG 7.52020-12-14
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
- CVE-2020-13700HIGHCVSS 7.5EG 7.52020-06-24
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive informa…
- CVE-2020-11589HIGHCVSS 7.5EG 7.52020-04-06
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users o…
- CVE-2019-19866HIGHCVSS 7.5EG 7.52020-02-21
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can e…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →