CWE-639 通过用户控制密钥绕过授权机制 类弱点 2041 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-639 属于授权绕过漏洞,指系统依赖用户可控的键值检索数据时,未验证该键值是否属于当前请求用户。攻击者通过篡改标识符(如ID),直接访问其他用户的数据记录。开发者应避免使用直接暴露的键值,转而采用间接引用或会话上下文验证,确保每次数据访问前严格校验资源归属权,从而防止越权访问。
... conn = new SqlConnection(_ConnectionString); conn.Open(); int16 id = System.Convert.ToInt16(invoiceID.Text); SqlCommand query = new SqlCommand( "SELECT * FROM invoices WHERE id = @id", conn); query.Parameters.AddWithValue("@id", id); SqlDataReader objReader = objCommand.ExecuteReader(); ...
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-6223 | WordPress Plugin LearnPress 安全漏洞 — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 4.3 | Medium | 2024-01-11 |
| CVE-2023-48783 | Fortinet PortiPortal 安全漏洞 — FortiPortal | 4.9 | Medium | 2024-01-10 |
| CVE-2023-49251 | Siemens SIMATIC CN 4100 安全漏洞 — SIMATIC CN 4100 | 8.8 | High | 2024-01-09 |
| CVE-2024-0264 | Clinic Queuing System 安全漏洞 — Clinic Queuing System | 7.3 | High | 2024-01-07 |
| CVE-2023-51502 | WordPress Plugin WooCommerce Stripe Payment Gateway 安全漏洞 — WooCommerce Stripe Payment Gateway | 7.5 | High | 2024-01-05 |
| CVE-2023-51503 | WordPress Plugin WooPayments 安全漏洞 — WooPayments – Fully Integrated Solution Built and Supported by Woo | 5.9 | Medium | 2023-12-31 |
| CVE-2023-46646 | GitHub Enterprise Server 安全漏洞 — Enterprise Server | 5.3 | Medium | 2023-12-21 |
| CVE-2023-49765 | WordPress plugin Rate my Post – WP Rating System 安全漏洞 — Rate my Post – WP Rating System | 4.3 | Medium | 2023-12-21 |
| CVE-2023-47191 | WordPress plugin Youzify 安全漏洞 — Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | 6.5 | Medium | 2023-12-21 |
| CVE-2023-32799 | WordPress plugin WooCommerce Ship to Multiple Addresses 安全漏洞 — Shipping Multiple Addresses | 6.5 | Medium | 2023-12-21 |
| CVE-2023-32747 | WordPress plugin WooCommerce Bookings 安全漏洞 — WooCommerce Bookings | 5.4 | Medium | 2023-12-21 |
| CVE-2023-35914 | WordPress Plugin Woo Subscriptions 安全漏洞 — Woo Subscriptions | 7.5 | High | 2023-12-20 |
| CVE-2023-35916 | WordPress Plugin WooPayments 安全漏洞 — WooPayments – Fully Integrated Solution Built and Supported by Woo | 7.5 | High | 2023-12-20 |
| CVE-2023-35876 | WordPress Plugin WooCommerce Square 安全漏洞 — WooCommerce Square | 8.1 | High | 2023-12-20 |
| CVE-2023-36520 | WordPress Plugin Editorial Calendar 安全漏洞 — Editorial Calendar | 5.4 | Medium | 2023-12-20 |
| CVE-2023-37871 | WordPress Plugin GoCardless 安全漏洞 — GoCardless | 8.2 | High | 2023-12-20 |
| CVE-2023-38513 | WordPress Plugin Photo Engine 安全漏洞 — Photo Engine (Media Organizer & Lightroom) | 5.4 | Medium | 2023-12-20 |
| CVE-2023-41796 | WordPress Plugin Sunshine Photo Cart 安全漏洞 — Sunshine Photo Cart: Free Client Galleries for Photographers | 5.3 | Medium | 2023-12-20 |
| CVE-2023-46311 | WordPress Plugin Comments 安全漏洞 — Comments – wpDiscuz | 2.7 | Low | 2023-12-20 |
| CVE-2023-6929 | EuroTel ETL3100 安全漏洞 — ETL3100 | 7.5 | High | 2023-12-19 |
| CVE-2022-43450 | WordPress Plugin Stream 安全漏洞 — Stream | 4.3 | Medium | 2023-12-19 |
| CVE-2023-49812 | WordPress plugin WP Photo Album Plus 安全漏洞 — WP Photo Album Plus | 5.3 | Medium | 2023-12-19 |
| CVE-2023-6341 | Catalis CMS360 安全漏洞 — CMS360 | 5.3 | Medium | 2023-11-30 |
| CVE-2023-6226 | WordPress Plugin Shortcodes Ultimate 安全漏洞 — WP Shortcodes Plugin — Shortcodes Ultimate | 4.3 | Medium | 2023-11-28 |
| CVE-2023-48304 | Nextcloud 安全漏洞 — security-advisories | 4.3 | Medium | 2023-11-21 |
| CVE-2023-6144 | DevBlog 安全漏洞 — Dev Blog | 9.1 | Critical | 2023-11-20 |
| CVE-2023-3869 | WordPress Plugin wpDiscuz 安全漏洞 — Comments – wpDiscuz | 5.3 | Medium | 2023-10-20 |
| CVE-2023-3998 | WordPress Plugin wpDiscuz 安全漏洞 — Comments – wpDiscuz | 5.3 | Medium | 2023-10-20 |
| CVE-2023-43668 | Apache InLong 代码问题漏洞 — Apache InLong | 9.8 | - | 2023-10-16 |
| CVE-2023-44981 | Apache ZooKeeper 安全漏洞 — Apache ZooKeeper | 9.1 | - | 2023-10-11 |
CWE-639(通过用户控制密钥绕过授权机制) 是常见的弱点类别,本平台收录该类弱点关联的 2041 条 CVE 漏洞。