Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) p
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowe
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize acces
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire anoth
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor wi
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki
Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to perm
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure d
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams inte
Windows Key Storage Provider Security Feature Bypass Vulnerability
Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive informati
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malici
kimai2 is vulnerable to Improper Access Control
https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected b
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in
Windows TCP/IP Driver Security Feature Bypass Vulnerability
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_ima
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modif
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploita
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Ob
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possib
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated at
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image ga
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uplo
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t
IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they sh
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users wit
vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify an
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any att
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authentica
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being aut
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app v
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint m
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the conf
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions st
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to by
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user in
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started