CWE-639 通过用户控制密钥绕过授权机制 类弱点 2041 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-639 属于授权绕过漏洞,指系统依赖用户可控的键值检索数据时,未验证该键值是否属于当前请求用户。攻击者通过篡改标识符(如ID),直接访问其他用户的数据记录。开发者应避免使用直接暴露的键值,转而采用间接引用或会话上下文验证,确保每次数据访问前严格校验资源归属权,从而防止越权访问。
... conn = new SqlConnection(_ConnectionString); conn.Open(); int16 id = System.Convert.ToInt16(invoiceID.Text); SqlCommand query = new SqlCommand( "SELECT * FROM invoices WHERE id = @id", conn); query.Parameters.AddWithValue("@id", id); SqlDataReader objReader = objCommand.ExecuteReader(); ...
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-0692 | WordPress和Elementor 安全漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 4.3 | Medium | 2023-06-09 |
| CVE-2023-1889 | WordPress Plugin Directorist 安全漏洞 — Directorist: AI-Powered Business Directory, Listings & Classified Ads | 6.5 | Medium | 2023-06-09 |
| CVE-2023-0691 | WordPress Plugin Metform Elementor Contact Form Builder 安全漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 4.3 | Medium | 2023-06-09 |
| CVE-2023-0688 | WordPress Plugin Metform Elementor Contact Form Builder 安全漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 6.5 | Medium | 2023-06-09 |
| CVE-2023-0693 | WordPress和Elementor 安全漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 6.5 | Medium | 2023-06-09 |
| CVE-2023-0694 | WordPress和Elementor 安全漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 6.5 | Medium | 2023-06-09 |
| CVE-2023-0985 | MB connect line mbCONNECT24和mymbCONNECT24 安全漏洞 — mbCONNECT24 | 8.8 | High | 2023-06-06 |
| CVE-2023-32310 | DataEase 安全漏洞 — dataease | 8.1 | High | 2023-06-01 |
| CVE-2023-2978 | Abstrium Pydio Cells 安全漏洞 — Pydio Cells | 4.6 | Medium | 2023-05-30 |
| CVE-2023-2883 | CBOT Chatbot 安全漏洞 — Chatbot | 8.8 | High | 2023-05-25 |
| CVE-2023-2065 | Armoli Technology Cargo Tracking System 安全漏洞 — Cargo Tracking System | 8.8 | High | 2023-05-24 |
| CVE-2023-2702 | Finex Media Competition Management System 安全漏洞 — Competition Management System | 8.8 | High | 2023-05-23 |
| CVE-2023-2844 | CloudExplorer Lite 安全漏洞 — cloudexplorer-dev/cloudexplorer-lite | 5.4 | - | 2023-05-23 |
| CVE-2023-2713 | Ideasoft E-commerce Platform 安全漏洞 — Rental Module | 9.8 | Critical | 2023-05-20 |
| CVE-2023-2276 | WordPress Plugin WCFM Membership 安全漏洞 — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace | 9.8 | Critical | 2023-05-20 |
| CVE-2023-2548 | WordPress plugin RegistrationMagic 安全漏洞 — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | 6.6 | Medium | 2023-05-16 |
| CVE-2023-31182 | EasyTor 安全漏洞 — EasyTor Applications | 8.1 | High | 2023-05-08 |
| CVE-2023-30550 | MeterSphere 安全漏洞 — metersphere | 6.8 | Medium | 2023-05-04 |
| CVE-2023-28656 | F5 BIG-IP 安全漏洞 — NGINX Instance Manager | 8.1 | High | 2023-05-03 |
| CVE-2023-2260 | alf.io 安全漏洞 — alfio-event/alf.io | 6.5 | - | 2023-04-24 |
| CVE-2023-24834 | WisdomGarden Tronclass 代码问题漏洞 — Tronclass ilearn | 6.5 | Medium | 2023-03-27 |
| CVE-2023-24842 | HGiga MailSherlock 安全漏洞 — MailSherlock | 5.3 | Medium | 2023-03-27 |
| CVE-2023-1462 | Vadi Corporate Information Systems 安全漏洞 — DigiKent | 8.8 | High | 2023-03-21 |
| CVE-2023-1463 | TeamPass 授权问题漏洞 — nilsteampassnet/teampass | 8.2 | - | 2023-03-17 |
| CVE-2023-28109 | Play With Docker 安全漏洞 — play-with-docker | 6.5 | Medium | 2023-03-16 |
| CVE-2023-0882 | Kron Single Connect 安全漏洞 — Single Connect | 8.8 | High | 2023-02-17 |
| CVE-2023-25160 | Nextcloud 安全漏洞 — security-advisories | 4.1 | Medium | 2023-02-13 |
| CVE-2023-0558 | WordPress plugin ContentStudio 安全漏洞 — ContentStudio | 8.2 | High | 2023-01-27 |
| CVE-2023-0550 | WordPress plugin Quick Restaurant Menu 安全漏洞 — Quick Restaurant Menu | 8.1 | High | 2023-01-27 |
| CVE-2023-22471 | Nextcloud 安全漏洞 — security-advisories | 3.5 | Low | 2023-01-14 |
CWE-639(通过用户控制密钥绕过授权机制) 是常见的弱点类别,本平台收录该类弱点关联的 2041 条 CVE 漏洞。