Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-05-30 CVE-2022-36247 Authorization Bypass Through User-Controlled Key vulnerability in Shopbeat Shop Beat Media Player
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
network
low complexity
shopbeat CWE-639
critical
9.1
2023-05-30 CVE-2023-2978 Authorization Bypass Through User-Controlled Key vulnerability in Abstrium Pydio Cells 4.2.0
A vulnerability was found in Abstrium Pydio Cells 4.2.0.
network
low complexity
abstrium CWE-639
4.3
2023-05-25 CVE-2023-2883 Authorization Bypass Through User-Controlled Key vulnerability in Cbot Core and Cbot Panel
Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
network
low complexity
cbot CWE-639
8.8
2023-05-24 CVE-2023-2065 Authorization Bypass Through User-Controlled Key vulnerability in Armoli Cargo Tracking System
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .
network
low complexity
armoli CWE-639
8.8
2023-05-23 CVE-2023-2702 Authorization Bypass Through User-Controlled Key vulnerability in Finexmedia Competition Management System
Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authentication Bypass.This issue affects Competition Management System: before 23.07.
network
low complexity
finexmedia CWE-639
8.8
2023-05-23 CVE-2023-2844 Authorization Bypass Through User-Controlled Key vulnerability in Fit2Cloud Cloudexplorer Lite
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
network
low complexity
fit2cloud CWE-639
4.9
2023-05-20 CVE-2023-2713 Authorization Bypass Through User-Controlled Key vulnerability in Rental Module Project Rental Module
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass.This issue affects Rental Module: before 23.05.15.
network
low complexity
rental-module-project CWE-639
critical
9.8
2023-05-20 CVE-2023-2276 Authorization Bypass Through User-Controlled Key vulnerability in Wclovers Wcfm Membership
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7.
network
low complexity
wclovers CWE-639
critical
9.8
2023-05-16 CVE-2023-2548 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss Registrationmagic
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5.
network
low complexity
metagauss CWE-639
7.2
2023-05-08 CVE-2023-31182 Authorization Bypass Through User-Controlled Key vulnerability in Easytor
EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified method.
network
low complexity
easytor CWE-639
critical
9.8