CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,417 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 3 of 49
- CVE-2020-11589HIGHCVSS 7.5EG 7.52020-04-06
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users o…
- CVE-2020-11658CRITICALCVSS 9.8EG 9.82020-04-15
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
- CVE-2020-11659MEDIUMCVSS 4.3EG 4.32020-04-15
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.
- CVE-2020-12643MEDIUMCVSS 4.3EG 4.32020-08-31
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
- CVE-2020-13357MEDIUMCVSS 4.3EG 4.32020-12-11
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
- CVE-2020-13462MEDIUMCVSS 5.7EG 5.72021-02-09
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.
- CVE-2020-13700HIGHCVSS 7.5EG 7.52020-06-24
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive informa…
- CVE-2020-13923MEDIUMCVSS 5.3EG 5.32020-07-15
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
- CVE-2020-13998MEDIUMCVSS 5.3EG 5.32020-06-11
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affe…
- CVE-2020-14174MEDIUMCVSS 4.3EG 4.32020-07-13
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versi…
- CVE-2020-15958HIGHCVSS 8.6EG 8.62020-09-18
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.
- CVE-2020-16088CRITICALCVSS 9.8EG 9.82020-07-28
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
- CVE-2020-16194MEDIUMCVSS 5.3EG 5.32021-02-04
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and in…
- CVE-2020-16240MEDIUMCVSS 5.3EG 5.32020-09-23
GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have access to such func…
- CVE-2020-19890MEDIUMCVSS 4.9EG 4.92020-08-24
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
- CVE-2020-20183HIGHCVSS 7.5EG 7.52020-12-14
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
- CVE-2020-23446MEDIUMCVSS 5.3EG 5.32020-09-22
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
- CVE-2020-23449HIGHCVSS 7.5EG 7.52021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
- CVE-2020-23722HIGHCVSS 8.8EG 8.82021-03-10
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
- CVE-2020-26068MEDIUMCVSS 5.5EG 5.52020-11-18
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient acce…
- CVE-2020-26171MEDIUMCVSS 4.3EG 4.32020-12-18
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.
- CVE-2020-26173LOWCVSS 3.1EG 3.12020-12-18
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.
- CVE-2020-26175MEDIUMCVSS 6.5EG 6.52020-12-18
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.
- CVE-2020-26178MEDIUMCVSS 5.3EG 5.32020-12-18
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.
- CVE-2020-26679MEDIUMCVSS 4.3EG 4.32021-05-26
vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their…
- CVE-2020-27662MEDIUMCVSS 4.3EG 4.32020-11-26
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
- CVE-2020-27663MEDIUMCVSS 4.3EG 4.32020-11-26
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
- CVE-2020-27742MEDIUMCVSS 6.5EG 6.52020-10-28
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly arch…
- CVE-2020-29156MEDIUMCVSS 5.3EG 5.32020-12-27
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
- CVE-2020-29446MEDIUMCVSS 5.3EG 5.32021-01-18
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
- CVE-2020-35849HIGHCVSS 7.5EG 7.52020-12-30
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potent…
- CVE-2020-36126HIGHCVSS 8.1EG 8.12021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTORE marketplace endpoints allow an authenticated user to read and write data not owned by th…
- CVE-2020-36231MEDIUMCVSS 4.3EG 4.32021-02-02
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before…
- CVE-2020-36895HIGHCVSS 7.5EG 7.52025-12-10
EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the Site…
- CVE-2020-36923CRITICALCVSS 9.8EG 9.82026-01-06
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating cl…
- CVE-2020-37008HIGHCVSS 7.5EG 7.52026-01-29
EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quote…
- CVE-2020-37094CRITICALCVSS 8.1EG 9.82026-02-03
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentic…
- CVE-2020-4918MEDIUMCVSS 4.4EG 4.42021-01-04
IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.
- CVE-2020-5194MEDIUMCVSS 5.4EG 5.42020-01-14
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_downloa…
- CVE-2020-5539MEDIUMCVSS 6.5EG 6.52020-03-02
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.
- CVE-2020-5743MEDIUMCVSS 4.3EG 4.32020-05-07
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.
- CVE-2020-6641MEDIUMCVSS 4.3EG 4.32021-06-02
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.
- CVE-2020-6859MEDIUMCVSS 5.3EG 5.32020-01-13
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified use…
- CVE-2020-7918MEDIUMCVSS 5.4EG 5.42020-03-27
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.
- CVE-2020-8154HIGHCVSS 7.7EG 7.72020-05-12
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
- CVE-2020-8235MEDIUMCVSS 4.3EG 4.32020-10-05
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
- CVE-2020-8297MEDIUMCVSS 4.3EG 4.32021-02-23
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.
- CVE-2020-8503MEDIUMCVSS 6.5EG 6.52020-01-31
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authenticated sender because of an error in a file-upload feature. This is fixed in 5.1.1068 and…
- CVE-2020-8791MEDIUMCVSS 6.5EG 6.52020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker can use their own t…
- CVE-2020-9384HIGHCVSS 8.8EG 8.82020-04-14
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST parameters. NOTE: This vuln…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →