CWE-639 通过用户控制密钥绕过授权机制 类弱点 2041 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-639 属于授权绕过漏洞,指系统依赖用户可控的键值检索数据时,未验证该键值是否属于当前请求用户。攻击者通过篡改标识符(如ID),直接访问其他用户的数据记录。开发者应避免使用直接暴露的键值,转而采用间接引用或会话上下文验证,确保每次数据访问前严格校验资源归属权,从而防止越权访问。
... conn = new SqlConnection(_ConnectionString); conn.Open(); int16 id = System.Convert.ToInt16(invoiceID.Text); SqlCommand query = new SqlCommand( "SELECT * FROM invoices WHERE id = @id", conn); query.Parameters.AddWithValue("@id", id); SqlDataReader objReader = objCommand.ExecuteReader(); ...
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-30513 | WordPress Plugin ProfileGrid 安全漏洞 — ProfileGrid | 6.5 | Medium | 2024-03-29 |
| CVE-2024-29020 | JumpServer 安全漏洞 — jumpserver | 4.6 | Medium | 2024-03-29 |
| CVE-2024-29024 | JumpServer 安全漏洞 — jumpserver | 4.6 | Medium | 2024-03-29 |
| CVE-2024-30507 | WordPress Plugin Molongui 安全漏洞 — Molongui | 2.7 | Low | 2024-03-29 |
| CVE-2024-1313 | Grafana 安全漏洞 — Grafana | 6.5 | Medium | 2024-03-26 |
| CVE-2024-29194 | OneUptime 安全漏洞 — oneuptime | 8.3 | High | 2024-03-24 |
| CVE-2024-2538 | WordPress Plugin Permalink Manager Lite 安全漏洞 — Permalink Manager Lite | 5.4 | Medium | 2024-03-20 |
| CVE-2024-1604 | BMC Control-M 安全漏洞 — Control-M | 6.4 | Medium | 2024-03-18 |
| CVE-2024-2577 | Employee Task Management System 安全漏洞 — Employee Task Management System | 7.3 | High | 2024-03-18 |
| CVE-2024-2576 | Employee Task Management System 安全漏洞 — Employee Task Management System | 7.3 | High | 2024-03-18 |
| CVE-2024-2575 | Employee Task Management System 安全漏洞 — Employee Task Management System | 7.3 | High | 2024-03-18 |
| CVE-2024-2574 | Employee Task Management System 安全漏洞 — Employee Task Management System | 7.3 | High | 2024-03-18 |
| CVE-2023-36483 | Carrier MASmobile 安全漏洞 — MASmobile Classic | 6.5 | Medium | 2024-03-16 |
| CVE-2023-6969 | WordPress Plugin User Shortcodes Plus 安全漏洞 — User Shortcodes Plus | 4.3 | Medium | 2024-03-13 |
| CVE-2024-1640 | WordPress Plugin Contact Form Builder 安全漏洞 — Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder | 5.3 | Medium | 2024-03-13 |
| CVE-2024-0839 | WordPress Plugin FeedWordPress 安全漏洞 — FeedWordPress | 5.3 | Medium | 2024-03-13 |
| CVE-2024-23112 | Fortinet FortiOS 和 FortiProxy 安全漏洞 — FortiOS | 7.2 | High | 2024-03-12 |
| CVE-2024-27302 | go-zero 安全漏洞 — go-zero | 9.1 | Critical | 2024-03-06 |
| CVE-2024-1470 | Micro Focus NetIQ Client Login Extension 安全漏洞 — NetIQ Client Login Extension | 7.1 | High | 2024-02-20 |
| CVE-2024-25983 | Moodle 安全漏洞 | 3.5 | Low | 2024-02-19 |
| CVE-2024-22455 | Dell E-Lab Navigator 安全漏洞 — Mobility - E-Lab Navigator | 4.4 | Medium | 2024-02-14 |
| CVE-2023-6724 | Hearing Tracking System 安全漏洞 — Hearing Tracking System | 8.8 | High | 2024-02-09 |
| CVE-2023-6515 | Mia Technology MIA-MED 安全漏洞 — MİA-MED | 8.8 | High | 2024-02-08 |
| CVE-2024-1075 | WordPress plugin Minimal Coming Soon 安全漏洞 — Minimal Coming Soon – Coming Soon Page | 3.7 | Low | 2024-02-05 |
| CVE-2023-6983 | WordPress plugin Display custom fields in the frontend 安全漏洞 — Display custom fields in the frontend – Post and User Profile Fields | 4.3 | Medium | 2024-02-05 |
| CVE-2024-22305 | WordPress plugin Contact Form builder with drag & drop for WordPress 安全漏洞 — Contact Form builder with drag & drop for WordPress – Kali Forms | 7.5 | High | 2024-01-31 |
| CVE-2024-0580 | QSIGE 安全漏洞 — Sinergia, Sinergia 2.0, and Sinergia Corporativo | 6.5 | Medium | 2024-01-18 |
| CVE-2023-6504 | WordPress Plugin User Profile Builder 安全漏洞 — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | 4.3 | Medium | 2024-01-11 |
| CVE-2023-6875 | WordPress Plugin POST SMTP Mailer 安全漏洞 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 9.8 | Critical | 2024-01-11 |
| CVE-2023-6506 | WordPress Plugin WP 2FA 安全漏洞 — WP 2FA – Two-factor authentication for WordPress | 4.3 | Medium | 2024-01-11 |
CWE-639(通过用户控制密钥绕过授权机制) 是常见的弱点类别,本平台收录该类弱点关联的 2041 条 CVE 漏洞。