CWE-639
Overview
- CWE ID
- 639
- CWE Name
- Authorization Bypass Through User-Controlled Key
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Incomplete
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.