VYPR

CWE-471

Modification of Assumed-Immutable Data (MAID)

BaseDraft

Description

The product does not properly protect an assumed-immutable element from being modified by an attacker.

This occurs when a particular input is critical enough to the functioning of the application that it should not be modifiable at all, but it is. Certain resources are often assumed to be immutable when they are not, such as hidden form fields in web applications, cookies, and reverse DNS lookups.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388

CVEs mapped to this weakness (40)

page 1 of 2
  • CVE-2026-50481CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

  • CVE-2022-25893CriDec 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.

  • CVE-2020-8158CriSep 18, 2020
    risk 0.64cvss 9.8epss 0.02

    Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

  • CVE-2020-8147CriApr 3, 2020
    risk 0.64cvss 9.8epss 0.03

    Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.

  • CVE-2022-21824HigFeb 24, 2022
    risk 0.55cvss 8.2epss 0.22

    Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The…

  • CVE-2024-55551HigMar 19, 2025
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code…

  • CVE-2018-3728HigMar 30, 2018
    risk 0.51cvss 8.8epss 0.04

    hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or…

  • CVE-2018-3723HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3722HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3720HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3719HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2024-9876HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.00

    : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

  • CVE-2023-2904HigJun 7, 2023
    risk 0.47cvss 7.3epss 0.01

    The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an…

  • CVE-2025-33136HigMay 22, 2025
    risk 0.46cvss 7.1epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

  • CVE-2020-26245HigNov 27, 2020
    risk 0.46cvss 8.1epss 0.02

    npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be…

  • CVE-2020-15256HigOct 19, 2020
    risk 0.43cvss 7.7epss 0.02

    A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of…

  • CVE-2024-34517MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.01

    The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

  • CVE-2023-43697MedOct 9, 2023
    risk 0.42cvss 6.5epss 0.01

    Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.

  • CVE-2021-37177MedSep 14, 2021
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system.

  • CVE-2020-28477HigJan 19, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package immer.