Weaknesses of type CWE-639

1,841 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2023-36520MEDIUMWordPress Editorial Calendar Plugin <= 3.7.12 is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.4%CVE-2021-36865LOWWordPress Quiz And Survey Master plugin <= 7.3.4 - Insecure direct object references (IDOR) vulnerabilityEPSS 0.4%CVE-2024-10868MEDIUMEnter Addons – Ultimate Template Builder for Elementor <= 2.1.9 - Authenticated (Contributor+) Post DisclosureEPSS 0.4%CVE-2025-26788HIGHStrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.EPSS 0.4%CVE-2024-43315HIGHWordPress Stripe Payments For WooCommerce plugin <= 1.9.1 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.4%CVE-2024-12116MEDIUMUnlimited Theme Addon For Elementor and WooCommerce <= 1.2.2 - Authenticated (Contributor+) Post DisclosureEPSS 0.4%CVE-2019-19755CRITICALethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identificatEPSS 0.4%CVE-2024-5977MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post ActionsEPSS 0.4%CVE-2023-47191MEDIUMWordPress Youzify Plugin <= 1.2.2 is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.4%CVE-2021-47721HIGHOrangescrum 1.8.0 Authenticated Privilege Escalation via User Session ManipulationEPSS 0.4%CVE-2024-50687CRITICALSunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService APIEPSS 0.4%CVE-2026-29002HIGHCouchCMS Privilege Escalation via f_k_levels_list ParameterEPSS 0.4%CVE-2025-12283MEDIUMcode-projects Client Details System authorizationEPSS 0.4%CVE-2026-50141HIGHWoodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonationEPSS 0.4%CVE-2026-35430HIGHAzure Privileged Identity Management (PIM) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-7286MEDIUMACF Quick Edit Fields <= 3.2.2 - Authenticated (Contributor+) Insecure Direct Object ReferenceEPSS 0.4%CVE-2026-2347CRITICALIDOR in Akıllı Ticaret's E-Commerce PackEPSS 0.4%CVE-2026-25497HIGHCraft has a GraphQL Asset Mutation Privilege EscalationEPSS 0.4%CVE-2024-7473HIGHIDOR Vulnerability in lunary-ai/lunaryEPSS 0.4%CVE-2026-32761MEDIUMFile Browser has an Authorization Policy Bypass in its Public Share Download FlowEPSS 0.4%