Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2022-01-03 CVE-2021-45428 Authorization Bypass Through User-Controlled Key vulnerability in Telesquare Tlr-2005Ksh Firmware
TLR-2005KSH is affected by an incorrect access control vulnerability.
network
low complexity
telesquare CWE-639
7.5
2021-12-28 CVE-2021-40579 Authorization Bypass Through User-Controlled Key vulnerability in Online Enrollment Management System Project Online Enrollment Management System 1.0
https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control.
6.5
2021-12-21 CVE-2021-24739 Authorization Bypass Through User-Controlled Key vulnerability in Shapedplugin Logo Carousel
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
network
low complexity
shapedplugin CWE-639
8.1
2021-12-14 CVE-2021-43828 Authorization Bypass Through User-Controlled Key vulnerability in Patrowl Patrowlmanager
PatrOwl is a free and open-source solution for orchestrating Security Operations.
network
low complexity
patrowl CWE-639
5.0
2021-12-14 CVE-2021-43820 Authorization Bypass Through User-Controlled Key vulnerability in Seafile Server
Seafile is an open source cloud storage system.
network
seafile CWE-639
4.3
2021-12-14 CVE-2021-44949 Authorization Bypass Through User-Controlled Key vulnerability in Glfusion 1.7.9
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
network
low complexity
glfusion CWE-639
critical
9.8
2021-12-13 CVE-2021-39916 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-639
4.0
2021-12-13 CVE-2021-39934 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-639
4.0
2021-12-01 CVE-2021-3964 Authorization Bypass Through User-Controlled Key vulnerability in Elgg
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
network
elgg CWE-639
4.3
2021-12-01 CVE-2021-3992 Authorization Bypass Through User-Controlled Key vulnerability in Kimai2 Project Kimai2
kimai2 is vulnerable to Improper Access Control
network
low complexity
kimai2-project CWE-639
4.0