VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (563)

page 28 of 29
  • CVE-2024-45299MedSep 6, 2024
    risk 0.00cvss 6.5epss 0.01

    alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped…

  • CVE-2024-8297MedAug 29, 2024
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper…

  • CVE-2024-27938MedMar 11, 2024
    risk 0.00cvss 5.3epss 0.01

    Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may allow incoming e-mails to be spoofed. This, in conjunction with a cooperative outgoing SMTP service, would allow for an incoming e-mail to be received by…

  • CVE-2023-38316CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2…

  • CVE-2023-46301CriOct 22, 2023
    risk 0.00cvss 9.8epss 0.01

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.

  • CVE-2023-46300CriOct 22, 2023
    risk 0.00cvss 9.8epss 0.01

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

  • CVE-2023-28101MedMar 16, 2023
    risk 0.00cvss 5.0epss 0.01

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the…

  • CVE-2023-28487MedMar 16, 2023
    risk 0.00cvss 5.3epss 0.01

    Sudo before 1.9.13 does not escape control characters in sudoreplay output.

  • CVE-2023-28486MedMar 16, 2023
    risk 0.00cvss 5.3epss 0.01

    Sudo before 1.9.13 does not escape control characters in log messages.

  • CVE-2022-41322HigSep 23, 2022
    risk 0.00cvss 7.8epss 0.01

    In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

  • CVE-2022-35153CriAug 18, 2022
    risk 0.00cvss 9.8epss 0.02

    FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

  • CVE-2022-23079Jun 22, 2022
    risk 0.00cvss —epss 0.01

    In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

  • CVE-2022-0935HigApr 7, 2022
    risk 0.00cvss 8.8epss 0.01

    Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.

  • CVE-2022-25235CriFeb 16, 2022
    risk 0.00cvss 9.8epss 0.05

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

  • CVE-2022-23603CriFeb 1, 2022
    risk 0.00cvss 9.9epss 0.01

    iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds…

  • CVE-2021-41191HigOct 27, 2021
    risk 0.00cvss 7.5epss 0.01

    Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in…

  • CVE-2021-39170HigSep 1, 2021
    risk 0.00cvss 8.0epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch…

  • CVE-2021-32812MedAug 2, 2021
    risk 0.00cvss 4.6epss 0.01

    Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in frontend HTTP server. The attacker can send in a carefully…

  • CVE-2021-32679LowJul 12, 2021
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`,…

  • CVE-2020-13654HigDec 31, 2020
    risk 0.00cvss 7.5epss 0.02

    XWiki Platform before 12.8 mishandles escaping in the property displayer.