VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (510)

page 12 of 26
  • CVE-2023-23599MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

  • CVE-2022-45143HigJan 3, 2023
    risk 0.42cvss 7.5epss 0.03

    The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that…

  • CVE-2020-36567HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.

  • CVE-2022-43883MedDec 19, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

  • CVE-2022-4011MedNov 16, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack may be…

  • CVE-2021-45848HigMar 15, 2022
    risk 0.42cvss 7.5epss 0.02

    Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.

  • CVE-2021-45226MedJan 24, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites.

  • CVE-2021-4068MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-40007MedDec 13, 2021
    risk 0.42cvss 6.5epss 0.01

    There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log output management. An attacker with the ability to access the log file of device may lead to information disclosure.

  • CVE-2021-42250MedNov 17, 2021
    risk 0.42cvss 6.5epss 0.02

    Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

  • CVE-2021-32072MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive application data) due to insufficient output sanitization. A successful exploit could allow an attacker to view source code methods.

  • CVE-2021-32067MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output sanitization.

  • CVE-2020-27604MedOct 21, 2020
    risk 0.42cvss 6.5epss 0.01

    BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an…

  • CVE-2020-6313MedSep 9, 2020
    risk 0.42cvss 6.5epss 0.01

    SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions…

  • CVE-2020-13625HigJun 8, 2020
    risk 0.42cvss 7.5epss 0.04

    PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

  • CVE-2009-4267MedFeb 19, 2018
    risk 0.42cvss 6.5epss 0.01

    The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.

  • CVE-2026-47173MedJun 11, 2026
    risk 0.41cvss epss 0.00

    Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a ticket with a reason containing @everyone, @here, user mentions, or role mentions. When the ticket is created, the bot posts the…

  • CVE-2024-0987MedJan 29, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for logs. The exploit has been disclosed to the public and may…

  • CVE-2022-29258HigMay 31, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3, XWiki…

  • CVE-2022-29252HigMay 25, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. The issue is…