Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2021-12-14 CVE-2021-43820 Authorization Bypass Through User-Controlled Key vulnerability in Seafile Server
Seafile is an open source cloud storage system.
network
high complexity
seafile CWE-639
5.9
2021-12-14 CVE-2021-44949 Authorization Bypass Through User-Controlled Key vulnerability in Glfusion 1.7.9
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
network
low complexity
glfusion CWE-639
critical
9.8
2021-12-13 CVE-2021-39916 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-639
4.3
2021-12-13 CVE-2021-39934 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-639
4.3
2021-12-01 CVE-2021-3964 Authorization Bypass Through User-Controlled Key vulnerability in Elgg
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
network
high complexity
elgg CWE-639
5.9
2021-12-01 CVE-2021-3992 Authorization Bypass Through User-Controlled Key vulnerability in Kimai2 Project Kimai2
kimai2 is vulnerable to Improper Access Control
network
low complexity
kimai2-project CWE-639
6.5
2021-11-30 CVE-2021-36329 Authorization Bypass Through User-Controlled Key vulnerability in Dell EMC Streaming Data Platform
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability.
network
low complexity
dell CWE-639
6.5
2021-11-23 CVE-2021-24892 Authorization Bypass Through User-Controlled Key vulnerability in Advanced Forms Project Advanced Forms
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account.
network
low complexity
advanced-forms-project CWE-639
8.8
2021-11-19 CVE-2021-22951 Authorization Bypass Through User-Controlled Key vulnerability in Concretecms Concrete CMS
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7.
network
low complexity
concretecms CWE-639
7.5
2021-11-19 CVE-2021-22967 Authorization Bypass Through User-Controlled Key vulnerability in Concretecms Concrete CMS
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H
network
low complexity
concretecms CWE-639
7.5