VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (785)

page 27 of 40
  • CVE-2024-21245MedJan 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-47165MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server is deployed locally, the `localhost_aliases` variable includes "null" as a valid origin. This allows…

  • CVE-2022-24762MedMar 14, 2022
    risk 0.35cvss 6.5epss 0.01

    sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurring in the same browser. This issue has…

  • CVE-2020-0695MedFeb 11, 2020
    risk 0.35cvss 5.4epss 0.01

    A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'.

  • CVE-2020-0647MedJan 14, 2020
    risk 0.35cvss 5.4epss 0.01

    A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.

  • CVE-2019-1447MedNov 12, 2019
    risk 0.35cvss 5.4epss 0.01

    A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445.

  • CVE-2019-1445MedNov 12, 2019
    risk 0.35cvss 5.4epss 0.01

    A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447.

  • CVE-2019-9817MedJul 23, 2019
    risk 0.35cvss 5.3epss 0.01

    Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

  • CVE-2019-9797MedApr 26, 2019
    risk 0.35cvss 5.3epss 0.01

    Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

  • CVE-2017-7808MedJun 11, 2018
    risk 0.35cvss 5.3epss 0.01

    A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.

  • CVE-2017-8650MedAug 8, 2017
    risk 0.35cvss 5.4epss 0.01

    Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to exploit a security feature bypass due to Microsoft Edge not properly enforcing same-origin policies, aka "Microsoft Edge Security Feature Bypass Vulnerability".

  • CVE-2017-8530MedJun 15, 2017
    risk 0.35cvss 5.4epss 0.02

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge does not properly enforce same-origin policies, aka "Microsoft Edge Security Feature…

  • CVE-2026-92360MedSep 16, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote…

  • CVE-2026-53656MedAug 21, 2026
    risk 0.34cvss 6.3epss 0.00

    FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/server/routes/media.py unconditionally return Access-Control-Allow-Origin: *.…

  • CVE-2026-6143MedApr 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted…

  • CVE-2026-27824MedFeb 27, 2026
    risk 0.34cvss 5.3epss 0.00

    calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the…

  • CVE-2026-1997MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an…

  • CVE-2025-12245MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote…

  • CVE-2025-52621MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.

  • CVE-2025-42998MedJun 10, 2025
    risk 0.34cvss 5.3epss 0.00

    The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and…