CWE-15
External Control of System or Configuration Setting
Description
One or more system settings or configuration elements can be externally controlled by a user.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-13 · CAPEC-146 · CAPEC-176 · CAPEC-203 · CAPEC-270 · CAPEC-271 · CAPEC-579 · CAPEC-69 · CAPEC-76 · CAPEC-77
CVEs mapped to this weakness (85)
page 5 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-50252 | Hig | 0.02 | 8.3 | 0.24 | Dec 12, 2023 | php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `` tag that references an `` tag, it merges the attributes from the `` tag to the `` tag. The problem pops up especially when the `href` attribute from the… | ||
| CVE-2026-46485 | Hig | 0.00 | 8.2 | 0.00 | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing… | ||
| CVE-2026-44768 | Med | 0.00 | 4.1 | 0.00 | Jul 14, 2026 | SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the… | ||
| CVE-2024-4326 | Cri | 0.00 | 9.8 | 0.01 | May 16, 2024 | A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to… | ||
| CVE-2023-4704 | Med | 0.00 | 4.9 | 0.01 | Sep 1, 2023 | External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
- risk 0.02cvss 8.3epss 0.24
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `` tag that references an `` tag, it merges the attributes from the `` tag to the `` tag. The problem pops up especially when the `href` attribute from the…
- risk 0.00cvss 8.2epss 0.00
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing…
- risk 0.00cvss 4.1epss 0.00
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the…
- risk 0.00cvss 9.8epss 0.01
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to…
- risk 0.00cvss 4.9epss 0.01
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.