Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2019-10-30 CVE-2019-8235 Authorization Bypass Through User-Controlled Key vulnerability in Magento
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions.
network
low complexity
magento CWE-639
4.0
2019-10-14 CVE-2019-17574 Authorization Bypass Through User-Controlled Key vulnerability in Code-Atlantic Popup Maker
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress.
network
low complexity
code-atlantic CWE-639
6.4
2019-10-09 CVE-2019-17382 Authorization Bypass Through User-Controlled Key vulnerability in Zabbix
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4.
network
low complexity
zabbix CWE-639
critical
9.1
2019-09-30 CVE-2019-17050 Authorization Bypass Through User-Controlled Key vulnerability in Thecontrolgroup Voyager
An issue was discovered in the Voyager package through 1.2.7 for Laravel.
network
low complexity
thecontrolgroup CWE-639
6.5
2019-09-23 CVE-2019-16723 Authorization Bypass Through User-Controlled Key vulnerability in Cacti
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
network
low complexity
cacti CWE-639
4.3
2019-09-18 CVE-2019-16403 Authorization Bypass Through User-Controlled Key vulnerability in Webkul Bagisto
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
network
low complexity
webkul CWE-639
6.5
2019-09-16 CVE-2019-15725 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1.
network
low complexity
gitlab CWE-639
5.0
2019-09-11 CVE-2019-14725 Authorization Bypass Through User-Controlled Key vulnerability in Control-Webpanel Webpanel 0.9.8.851
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail usage value of a victim account via an attacker account.
network
low complexity
control-webpanel CWE-639
4.3
2019-09-11 CVE-2019-14724 Authorization Bypass Through User-Controlled Key vulnerability in Control-Webpanel Webpanel 0.9.8.851
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination of a victim's account via an attacker account.
network
low complexity
control-webpanel CWE-639
7.5
2019-09-10 CVE-2019-14721 Authorization Bypass Through User-Controlled Key vulnerability in Control-Webpanel Webpanel 0.9.8.851
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin via an attacker account.
network
low complexity
control-webpanel CWE-639
6.5