VYPR

CWE-15

External Control of System or Configuration Setting

BaseIncomplete

Description

One or more system settings or configuration elements can be externally controlled by a user.

Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-146 · CAPEC-176 · CAPEC-203 · CAPEC-270 · CAPEC-271 · CAPEC-579 · CAPEC-69 · CAPEC-76 · CAPEC-77

CVEs mapped to this weakness (85)

page 5 of 5
  • CVE-2023-50252HigDec 12, 2023
    risk 0.02cvss 8.3epss 0.24

    php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `` tag that references an `` tag, it merges the attributes from the `` tag to the `` tag. The problem pops up especially when the `href` attribute from the…

  • CVE-2026-46485HigJul 15, 2026
    risk 0.00cvss 8.2epss 0.00

    Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing…

  • CVE-2026-44768MedJul 14, 2026
    risk 0.00cvss 4.1epss 0.00

    SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the…

  • CVE-2024-4326CriMay 16, 2024
    risk 0.00cvss 9.8epss 0.01

    A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to…

  • CVE-2023-4704MedSep 1, 2023
    risk 0.00cvss 4.9epss 0.01

    External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.