Vulnerabilities (CVE)

Filtered by CWE-639
Total 937 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3286 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 7.7 HIGH
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.
CVE-2023-3285 2024-11-21 N/A 7.7 HIGH
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.
CVE-2023-3219 1 Myeventon 1 Eventon 2024-11-21 N/A 5.3 MEDIUM
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
CVE-2023-3133 1 Themeum 1 Tutor Lms 2024-11-21 N/A 7.5 HIGH
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
CVE-2023-3105 1 Learndash 1 Learndash 2024-11-21 N/A 8.8 HIGH
The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts.
CVE-2023-3066 1 Mobatime 1 Amxgt 100 2024-11-21 N/A 8.1 HIGH
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mobatime mobile application AMXGT100: through 1.3.20.
CVE-2023-3063 1 Smartypantsplugins 1 Sp Project \& Document Manager 2024-11-21 N/A 8.8 HIGH
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.
CVE-2023-3048 1 Tmtmakine 2 Lockcell, Lockcell Firmware 2024-11-21 N/A 9.8 CRITICAL
Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass.This issue affects Lockcell: before 15.
CVE-2023-38965 1 Oretnom23 1 Lost And Found Information System 2024-11-21 N/A 9.8 CRITICAL
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
CVE-2023-38884 1 Os4ed 1 Opensis 2024-11-21 N/A 7.5 HIGH
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
CVE-2023-38872 1 Economizzer 1 Economizzer 2024-11-21 N/A 3.7 LOW
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
CVE-2023-38513 1 Meowapps 1 Photo Engine 2024-11-21 N/A 5.4 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.
CVE-2023-38257 1 Iagona 1 Scrutisweb 2024-11-21 N/A 7.5 HIGH
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
CVE-2023-38201 3 Fedoraproject, Keylime, Redhat 9 Fedora, Keylime, Enterprise Linux and 6 more 2024-11-21 N/A 6.5 MEDIUM
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database.
CVE-2023-38055 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.6 CRITICAL
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
CVE-2023-38054 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.9 CRITICAL
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation.
CVE-2023-38053 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.9 CRITICAL
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
CVE-2023-38052 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.9 CRITICAL
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.
CVE-2023-38051 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.9 CRITICAL
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.
CVE-2023-38050 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.1 CRITICAL
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.