VYPR

CWE-140

Improper Neutralization of Delimiters

BaseDraft

Description

The product does not neutralize or incorrectly neutralizes delimiters.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-15

CVEs mapped to this weakness (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-33456Hig0.497.60.00Apr 10, 2026Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.
CVE-2026-33457Med0.416.30.00Apr 10, 2026Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.
CVE-2026-33455Med0.416.30.00Apr 10, 2026Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.