VYPR

CWE-472

External Control of Assumed-Immutable Web Parameter

BaseDraft

Description

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-146 · CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (145)

page 7 of 8
  • CVE-2025-31327MedApr 22, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not…

  • CVE-2025-31333MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.

  • CVE-2024-50703MedDec 30, 2024
    risk 0.28cvss 5.4epss 0.00

    TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

  • CVE-2024-3649MedMay 2, 2024
    risk 0.28cvss 5.3epss 0.01

    The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated…

  • CVE-2024-22049MedJan 4, 2024
    risk 0.28cvss 5.3epss 0.01

    httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

  • CVE-2022-30597MedMay 18, 2022
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • CVE-2026-59817MedJul 9, 2026
    risk 0.27cvss 5.3epss 0.00

    Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or…

  • CVE-2026-7912MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-32699MedMay 5, 2026
    risk 0.27cvss epss 0.00

    FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass…

  • CVE-2026-2519MedApr 9, 2026
    risk 0.27cvss 5.3epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation…

  • CVE-2025-3743MedApr 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the…

  • CVE-2023-24373LowJun 3, 2024
    risk 0.24cvss 3.7epss 0.00

    External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

  • CVE-2020-1765LowJan 10, 2020
    risk 0.23cvss 3.5epss 0.01

    An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions;…

  • CVE-2025-32816LowApr 11, 2025
    risk 0.13cvss 3.1epss 0.00

    CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.

  • CVE-2025-27893LowMar 11, 2025
    risk 0.12cvss 1.8epss 0.00

    In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. NOTE: the Supplier analyzed the…

  • CVE-2025-59382LowJun 10, 2026
    risk 0.08cvss epss 0.00

    QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

  • CVE-2026-1982MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured…

  • CVE-2026-7484MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: before 202606251646.

  • CVE-2026-65052HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured…

  • CVE-2026-56877MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch…