CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,416 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 4 of 49
- CVE-2020-9468MEDIUMCVSS 4.3EG 4.32020-03-26
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.
- CVE-2021-20599CRITICALCVSS 9.1EG 9.12021-10-14
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/1…
- CVE-2021-21012MEDIUMCVSS 5.3EG 5.32021-01-13
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information discl…
- CVE-2021-21013HIGHCVSS 8.1EG 8.12021-01-13
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information d…
- CVE-2021-21022MEDIUMCVSS 5.3EG 5.32021-02-11
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricte…
- CVE-2021-21255MEDIUMCVSS 5.8EG 5.82021-03-02
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. T…
- CVE-2021-21324MEDIUMCVSS 6.8EG 6.82021-03-08
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 there is an Insecure Direct Object Reference (IDOR) on "Solutio…
- CVE-2021-22023HIGHCVSS 7.2EG 7.22021-08-30
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an…
- CVE-2021-22906MEDIUMCVSS 6.5EG 6.52021-06-11
Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated users to lock files of other users.
- CVE-2021-22951HIGHCVSS 7.5EG 7.52021-11-19
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file…
- CVE-2021-22967HIGHCVSS 7.5EG 7.52021-11-19
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files …
- CVE-2021-24318MEDIUMCVSS 6.5EG 6.52021-06-01
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.
- CVE-2021-24374MEDIUMCVSS 5.3EG 5.32021-06-21
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module …
- CVE-2021-24473MEDIUMCVSS 5.4EG 5.42021-08-02
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those w…
- CVE-2021-24562HIGHCVSS 7.5EG 7.52021-08-23
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
- CVE-2021-24655HIGHCVSS 7.5EG 7.52022-07-17
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user k…
- CVE-2021-24739HIGHCVSS 8.1EG 8.12021-12-21
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
- CVE-2021-24800MEDIUMCVSS 4.3EG 4.32022-04-25
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
- CVE-2021-24840MEDIUMCVSS 5.3EG 5.32021-11-08
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could…
- CVE-2021-24892HIGHCVSS 8.8EG 8.82021-11-23
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of Wo…
- CVE-2021-25096MEDIUMCVSS 6.5EG 6.52022-02-07
The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL
- CVE-2021-26024MEDIUMCVSS 5.3EG 5.32021-02-03
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
- CVE-2021-27700HIGHCVSS 7.6EG 7.62024-11-12
SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another customer dashboard and perform actions like modify user, delete user, etc.
- CVE-2021-29773MEDIUMCVSS 5.4EG 5.42021-09-15
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865.
- CVE-2021-31927MEDIUMCVSS 4.3EG 4.32021-06-10
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. …
- CVE-2021-31970MEDIUMCVSS 5.5EG 5.52021-06-08
Windows TCP/IP Driver Security Feature Bypass Vulnerability
- CVE-2021-32654HIGHCVSS 8.1EG 8.12021-06-01
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive write/read privileges on any Federated File Share. Since public links can be added as fede…
- CVE-2021-32744CRITICALCVSS 9.8EG 9.82021-07-21
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor…
- CVE-2021-33223HIGHCVSS 8.8EG 8.82023-06-07
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.
- CVE-2021-3380MEDIUMCVSS 6.5EG 6.52021-11-10
Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.
- CVE-2021-33981MEDIUMCVSS 4.3EG 4.32021-09-08
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and im…
- CVE-2021-35337MEDIUMCVSS 4.3EG 4.32021-07-01
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
- CVE-2021-36032HIGHCVSS 8.3EG 8.32021-09-01
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/…
- CVE-2021-36329MEDIUMCVSS 6.5EG 6.52021-11-30
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.
- CVE-2021-36387MEDIUMCVSS 5.4EG 5.42021-10-14
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".
- CVE-2021-36388HIGHCVSS 7.5EG 7.52021-10-14
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".
- CVE-2021-36389HIGHCVSS 7.5EG 7.52021-10-14
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".
- CVE-2021-36400MEDIUMCVSS 5.3EG 5.32023-03-06
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
- CVE-2021-36539MEDIUMCVSS 6.5EG 6.52023-01-26
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).
- CVE-2021-36801HIGHCVSS 8.1EG 8.12021-08-04
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.
- CVE-2021-36865MEDIUMCVSS 3.8EG 4.32022-09-30
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
- CVE-2021-36874HIGHCVSS 7.1EG 7.12021-09-27
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
- CVE-2021-36906HIGHCVSS 2.7EG 8.82022-11-03
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
- CVE-2021-37184CRITICALCVSS 9.8EG 9.82021-09-14
A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of any user in the system under certain circumstances. With this an attacker could impersona…
- CVE-2021-37212MEDIUMCVSS 5.4EG 5.42021-08-09
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bu…
- CVE-2021-37213MEDIUMCVSS 4.3EG 4.32021-08-09
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access partic…
- CVE-2021-37214HIGHCVSS 8.8EG 8.82021-08-09
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access e…
- CVE-2021-37215MEDIUMCVSS 4.3EG 4.32021-08-09
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s use…
- CVE-2021-37331MEDIUMCVSS 5.3EG 5.32021-10-04
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by c…
- CVE-2021-37577MEDIUMCVSS 6.8EG 6.82024-10-01
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →