Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-07-17 CVE-2023-3700 Authorization Bypass Through User-Controlled Key vulnerability in Easyappointments
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
network
low complexity
easyappointments CWE-639
4.3
2023-07-13 CVE-2023-2190 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1.
network
low complexity
gitlab CWE-639
6.5
2023-07-10 CVE-2023-3219 Authorization Bypass Through User-Controlled Key vulnerability in Myeventon Eventon
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
network
low complexity
myeventon CWE-639
5.3
2023-07-06 CVE-2023-37242 Authorization Bypass Through User-Controlled Key vulnerability in Huawei Emui and Harmonyos
Vulnerability of commands from the modem being intercepted in the atcmdserver module.
network
low complexity
huawei CWE-639
critical
9.8
2023-07-05 CVE-2022-42175 Authorization Bypass Through User-Controlled Key vulnerability in Soluslabs Solusvm 4.1.2
Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other customer servers without authorization.
network
low complexity
soluslabs CWE-639
8.8
2023-06-23 CVE-2023-23679 Authorization Bypass Through User-Controlled Key vulnerability in Jshelpdesk
Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk: from n/a through 2.7.7.
network
low complexity
jshelpdesk CWE-639
8.8
2023-06-20 CVE-2023-26428 Authorization Bypass Through User-Controlled Key vulnerability in Open-Xchange Appsuite Backend
Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context.
network
low complexity
open-xchange CWE-639
6.5
2023-06-14 CVE-2023-34000 Authorization Bypass Through User-Controlled Key vulnerability in Woocommerce Stripe Payment Gateway
Unauth.
network
low complexity
woocommerce CWE-639
7.5
2023-06-13 CVE-2023-3048 Authorization Bypass Through User-Controlled Key vulnerability in Tmtmakine Lockcell Firmware
Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass.This issue affects Lockcell: before 15.
network
low complexity
tmtmakine CWE-639
critical
9.8
2023-06-07 CVE-2021-33223 Authorization Bypass Through User-Controlled Key vulnerability in Seeddms 6.0.15
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.
network
low complexity
seeddms CWE-639
8.8