Vulnerabilities (CVE)

Filtered by CWE-639
Total 845 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2367 1 Wsm Downloader Project 1 Wsm Downloader 2024-11-21 N/A 7.5 HIGH
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation
CVE-2022-2243 1 Gitlab 1 Gitlab 2024-11-21 4.0 MEDIUM 5.0 MEDIUM
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
CVE-2022-2198 1 2code 1 Wpqa Builder 2024-11-21 N/A 4.3 MEDIUM
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.
CVE-2022-2193 1 Hypr 1 Hypr Server 2024-11-21 N/A 7.5 HIGH
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions prior to 6.14.1.
CVE-2022-2080 1 Automattic 1 Sensei Lms 2024-11-21 N/A 4.3 MEDIUM
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student
CVE-2022-2034 1 Automattic 1 Sensei Lms 2024-11-21 N/A 5.3 MEDIUM
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
CVE-2022-29627 1 Online Market Place Site Project 1 Online Market Place Site 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.
CVE-2022-29287 1 Kentico 1 Kentico 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).
CVE-2022-29159 1 Nextcloud 1 Deck 2024-11-21 4.0 MEDIUM 5.0 MEDIUM
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1. There are no known currently-known workarounds available.
CVE-2022-29008 1 Bus Pass Management System Project 1 Bus Pass Management System 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
CVE-2022-28986 1 Lmsdoctor 1 2 Factor Authentication 2024-11-21 5.0 MEDIUM 7.5 HIGH
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
CVE-2022-27247 1 Cdsoft 1 Winhotel.mx 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.
CVE-2022-27108 1 Orangehrm 1 Orangehrm 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
CVE-2022-26665 1 Tylertech 1 Odyssey Portal 2024-11-21 5.0 MEDIUM 7.5 HIGH
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
CVE-2022-26254 1 Wowonder 1 Wowonder 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.
CVE-2022-25471 1 Open-emr 1 Openemr 2024-11-21 5.5 MEDIUM 8.1 HIGH
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.
CVE-2022-25336 1 Ibexa 1 Ez Platform Kernel 2024-11-21 4.3 MEDIUM 5.3 MEDIUM
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
CVE-2022-24979 1 Mittwald 1 Varnishcache 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.
CVE-2022-24401 1 Midnightblue 1 Tetra\ 2024-11-21 N/A 8.8 HIGH
Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthenticated manner. An active adversary can manipulate the view of these counters in a mobile station, provoking keystream re-use. By sending crafted messages to the MS and analyzing MS responses, keystream for arbitrary frames can be recovered.
CVE-2022-24400 1 Midnightblue 1 Tetra\ 2024-11-21 N/A 7.5 HIGH
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.