Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2024-01-03 CVE-2023-50342 Authorization Bypass Through User-Controlled Key vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.
network
low complexity
hcltech CWE-639
4.3
2024-01-02 CVE-2023-45892 Authorization Bypass Through User-Controlled Key vulnerability in Floorsightsoftware Insight Q32023
An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
network
low complexity
floorsightsoftware CWE-639
7.5
2024-01-02 CVE-2023-45893 Authorization Bypass Through User-Controlled Key vulnerability in Floorsightsoftware Customer Portal Q32023
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
network
low complexity
floorsightsoftware CWE-639
7.5
2023-12-31 CVE-2023-51503 Authorization Bypass Through User-Controlled Key vulnerability in Automattic Woopayments
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
network
low complexity
automattic CWE-639
7.5
2023-12-28 CVE-2023-50267 Authorization Bypass Through User-Controlled Key vulnerability in Metersphere
MeterSphere is a one-stop open source continuous testing platform.
network
low complexity
metersphere CWE-639
4.3
2023-12-21 CVE-2023-46646 Authorization Bypass Through User-Controlled Key vulnerability in Github Enterprise Server
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint.
network
low complexity
github CWE-639
5.3
2023-12-21 CVE-2023-32747 Authorization Bypass Through User-Controlled Key vulnerability in Automattic Woocommerce Bookings 1.15.78
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.
network
low complexity
automattic CWE-639
7.5
2023-12-21 CVE-2023-32799 Authorization Bypass Through User-Controlled Key vulnerability in Woocommerce Shipping multiple Addresses
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.
network
low complexity
woocommerce CWE-639
6.5
2023-12-21 CVE-2023-47191 Authorization Bypass Through User-Controlled Key vulnerability in Kainelabs Youzify
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.
network
low complexity
kainelabs CWE-639
6.5
2023-12-21 CVE-2023-49765 Authorization Bypass Through User-Controlled Key vulnerability in Blazzdev Rate MY Post
Authorization Bypass Through User-Controlled Key vulnerability in Blaz K.
network
low complexity
blazzdev CWE-639
6.5