Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-06-06 CVE-2023-0985 Authorization Bypass Through User-Controlled Key vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account.
network
low complexity
mbconnectline CWE-639
8.8
2023-06-05 CVE-2023-33956 Authorization Bypass Through User-Controlled Key vulnerability in Kanboard
Kanboard is open source project management software that focuses on the Kanban methodology.
network
low complexity
kanboard CWE-639
6.5
2023-06-05 CVE-2023-3066 Authorization Bypass Through User-Controlled Key vulnerability in Mobatime Amxgt 100 1.3.20
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mobatime mobile application AMXGT100: through 1.3.20.
network
low complexity
mobatime CWE-639
8.1
2023-06-01 CVE-2023-32310 Authorization Bypass Through User-Controlled Key vulnerability in Dataease
DataEase is an open source data visualization and analysis tool.
network
low complexity
dataease CWE-639
8.1
2023-05-30 CVE-2022-36247 Authorization Bypass Through User-Controlled Key vulnerability in Shopbeat Shop Beat Media Player 2.5.95
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
network
low complexity
shopbeat CWE-639
critical
9.1
2023-05-30 CVE-2023-2978 Authorization Bypass Through User-Controlled Key vulnerability in Abstrium Pydio Cells 4.2.0
A vulnerability was found in Abstrium Pydio Cells 4.2.0.
network
low complexity
abstrium CWE-639
4.3
2023-05-25 CVE-2023-2883 Authorization Bypass Through User-Controlled Key vulnerability in Cbot Core and Cbot Panel
Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
network
low complexity
cbot CWE-639
8.8
2023-05-24 CVE-2023-2065 Authorization Bypass Through User-Controlled Key vulnerability in Armoli Cargo Tracking System
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .
network
low complexity
armoli CWE-639
8.8
2023-05-23 CVE-2023-2702 Authorization Bypass Through User-Controlled Key vulnerability in Finexmedia Competition Management System
Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authentication Bypass.This issue affects Competition Management System: before 23.07.
network
low complexity
finexmedia CWE-639
8.8
2023-05-23 CVE-2023-2844 Authorization Bypass Through User-Controlled Key vulnerability in Fit2Cloud Cloudexplorer Lite
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
network
low complexity
fit2cloud CWE-639
4.9