Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-48641 Authorization Bypass Through User-Controlled Key vulnerability in Archerirm Archer
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability.
network
low complexity
archerirm CWE-639
8.8
2023-11-30 CVE-2023-6341 Authorization Bypass Through User-Controlled Key vulnerability in Catalisgov Cms360
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs.
network
low complexity
catalisgov CWE-639
5.3
2023-11-28 CVE-2023-6226 Authorization Bypass Through User-Controlled Key vulnerability in Getshortcodes Shortcodes Ultimate
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'.
network
low complexity
getshortcodes CWE-639
4.3
2023-11-24 CVE-2023-49298 Authorization Bypass Through User-Controlled Key vulnerability in Openzfs
OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms.
network
low complexity
openzfs CWE-639
7.5
2023-11-24 CVE-2023-33706 Authorization Bypass Through User-Controlled Key vulnerability in Sysaid
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
network
low complexity
sysaid CWE-639
6.5
2023-11-22 CVE-2023-47316 Authorization Bypass Through User-Controlled Key vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control.
network
low complexity
h-mdm CWE-639
5.4
2023-11-20 CVE-2023-38884 Authorization Bypass Through User-Controlled Key vulnerability in Os4Ed Opensis 9.0
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
network
low complexity
os4ed CWE-639
7.5
2023-11-14 CVE-2023-43900 Authorization Bypass Through User-Controlled Key vulnerability in Emsigner 2.8.7
Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
network
low complexity
emsigner CWE-639
6.5
2023-11-14 CVE-2023-46446 Authorization Bypass Through User-Controlled Key vulnerability in Asyncssh Project Asyncssh
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
network
high complexity
asyncssh-project CWE-639
6.8
2023-11-09 CVE-2023-5544 Authorization Bypass Through User-Controlled Key vulnerability in multiple products
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
network
low complexity
moodle redhat fedoraproject CWE-639
5.4