Total
859 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-13605 | 1 Control-webpanel | 1 Webpanel | 2024-11-21 | N/A |
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360. | ||||
CVE-2019-13461 | 1 Prestashop | 1 Prestashop | 2024-11-21 | N/A |
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444. | ||||
CVE-2019-13360 | 1 Control-webpanel | 1 Webpanel | 2024-11-21 | N/A |
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username. | ||||
CVE-2019-13337 | 1 Weseek | 1 Growi | 2024-11-21 | N/A |
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic authentication is required. | ||||
CVE-2019-12866 | 1 Jetbrains | 1 Youtrack | 2024-11-21 | N/A |
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168. | ||||
CVE-2019-12782 | 1 Thoughtspot | 1 Thoughtspot | 2024-11-21 | N/A |
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them. | ||||
CVE-2019-12742 | 1 Bludit | 1 Bludit | 2024-11-21 | N/A |
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/controllers/user-password.php Insecure Direct Object Reference (a modified username POST parameter). | ||||
CVE-2019-12252 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2024-11-21 | 6.5 Medium |
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring. | ||||
CVE-2019-10108 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels. | ||||
CVE-2018-20405 | 1 Bigtreecms | 1 Bigtree | 2024-11-21 | 2.7 Low |
BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system where cross site scripting is not an issue -- you already have full control of the CMS including running arbitrary PHP. | ||||
CVE-2018-19584 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups. | ||||
CVE-2018-19582 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user. | ||||
CVE-2018-19575 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue. | ||||
CVE-2018-18976 | 1 Ascensia | 1 Contour Diabetes | 2024-11-21 | N/A |
An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud platform by performing Direct Object References with a series of user ID values. (This information can be decrypted through a different vulnerability.) | ||||
CVE-2018-16971 | 1 Wisetail | 1 Learning Management System | 2024-11-21 | N/A |
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter. | ||||
CVE-2018-16704 | 1 Gleeztech | 1 Gleezcms | 2024-11-21 | N/A |
An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possible for attackers (logged in users) to view profile page of other users, as demonstrated by navigating to user/3 on demo.gleezcms.org. | ||||
CVE-2018-16608 | 1 Monstra | 1 Monstra | 2024-11-21 | N/A |
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&user_id=1, Insecure Direct Object Reference (IDOR). | ||||
CVE-2018-16606 | 1 Proconf | 1 Proconf | 2024-11-21 | N/A |
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter). | ||||
CVE-2018-15833 | 1 Vanillaforums | 1 Vanilla Forums | 2024-11-21 | N/A |
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items). | ||||
CVE-2018-10211 | 1 Vaultize | 1 Enterprise File Sharing | 2024-11-21 | N/A |
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie. |