Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2022-29008 Authorization Bypass Through User-Controlled Key vulnerability in PHPgurukul BUS Pass Management System 1.0
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
network
low complexity
phpgurukul CWE-639
6.5
2022-05-10 CVE-2022-28986 Authorization Bypass Through User-Controlled Key vulnerability in Lmsdoctor 2 Factor Authentication 2021072900
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
network
low complexity
lmsdoctor CWE-639
5.0
2022-05-01 CVE-2022-23061 Authorization Bypass Through User-Controlled Key vulnerability in Shopizer
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
network
low complexity
shopizer CWE-639
5.5
2022-04-25 CVE-2021-24800 Authorization Bypass Through User-Controlled Key vulnerability in Designwall DW Question & Answer
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
network
low complexity
designwall CWE-639
4.0
2022-04-25 CVE-2022-1461 Authorization Bypass Through User-Controlled Key vulnerability in Open-Emr Openemr
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
network
low complexity
open-emr CWE-639
4.0
2022-04-25 CVE-2022-1459 Authorization Bypass Through User-Controlled Key vulnerability in Open-Emr Openemr
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
network
low complexity
open-emr CWE-639
5.5
2022-04-18 CVE-2022-26665 Authorization Bypass Through User-Controlled Key vulnerability in Tylertech Odyssey Portal
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20.
network
low complexity
tylertech CWE-639
5.0
2022-04-16 CVE-2022-29287 Authorization Bypass Through User-Controlled Key vulnerability in Kentico
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability.
network
low complexity
kentico CWE-639
4.0
2022-04-14 CVE-2022-22190 Authorization Bypass Through User-Controlled Key vulnerability in Juniper Paragon Active Assurance Control Center 3.1.0
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information.
network
low complexity
juniper CWE-639
7.5
2022-04-07 CVE-2021-46416 Authorization Bypass Through User-Controlled Key vulnerability in SMA Sunny Tripower Firmware 3.10.16.R
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
network
low complexity
sma CWE-639
5.5