Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-04-15 CVE-2018-17455 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1.
network
low complexity
gitlab CWE-639
7.5
2023-04-14 CVE-2022-45175 Authorization Bypass Through User-Controlled Key vulnerability in Liveboxcloud Vdesk 018
An issue was discovered in LIVEBOX Collaboration vDesk through v018.
network
low complexity
liveboxcloud CWE-639
6.5
2023-04-05 CVE-2023-0967 Authorization Bypass Through User-Controlled Key vulnerability in Imaworldhealth Bhima 1.27.0
Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator.
network
low complexity
imaworldhealth CWE-639
6.5
2023-04-04 CVE-2023-1749 Authorization Bypass Through User-Controlled Key vulnerability in Getnexx products
The listed versions of Nexx Smart Home devices lack proper access control when executing actions.
network
low complexity
getnexx CWE-639
6.5
2023-04-04 CVE-2023-1750 Authorization Bypass Through User-Controlled Key vulnerability in Getnexx products
The listed versions of Nexx Smart Home devices lack proper access control when executing actions.
network
low complexity
getnexx CWE-639
7.1
2023-03-29 CVE-2023-26984 Authorization Bypass Through User-Controlled Key vulnerability in Peppermint 0.2.4
An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.
network
low complexity
peppermint CWE-639
8.1
2023-03-24 CVE-2023-24625 Authorization Bypass Through User-Controlled Key vulnerability in Ladybirdweb Faveo Servicedesk 5.0.1
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
network
low complexity
ladybirdweb CWE-639
6.5
2023-03-24 CVE-2023-28686 Authorization Bypass Through User-Controlled Key vulnerability in multiple products
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message.
network
low complexity
dino fedoraproject debian CWE-639
7.1
2023-03-23 CVE-2023-28334 Authorization Bypass Through User-Controlled Key vulnerability in Moodle
Authenticated users were able to enumerate other users' names via the learning plans page.
network
low complexity
moodle CWE-639
4.3
2023-03-21 CVE-2023-1462 Authorization Bypass Through User-Controlled Key vulnerability in Vadi Digikent
Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentication Abuse. This issue affects DigiKent: before 23.03.20.
network
low complexity
vadi CWE-639
8.8