VYPR

CWE-472

External Control of Assumed-Immutable Web Parameter

BaseDraft

Description

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-146 · CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (152)

page 7 of 8
  • CVE-2026-7969MedMay 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7942MedMay 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-7340MedApr 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-4453MedMar 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-54551MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the…

  • CVE-2025-54832MedJul 31, 2025
    risk 0.28cvss 4.3epss 0.00

    OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.

  • CVE-2025-43002MedMay 13, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.

  • CVE-2025-31327MedApr 22, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not…

  • CVE-2025-31333MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.

  • CVE-2024-50703MedDec 30, 2024
    risk 0.28cvss 5.4epss 0.00

    TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

  • CVE-2024-3649MedMay 2, 2024
    risk 0.28cvss 5.3epss 0.01

    The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated…

  • CVE-2024-22049MedJan 4, 2024
    risk 0.28cvss 5.3epss 0.01

    httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

  • CVE-2022-30597MedMay 18, 2022
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • CVE-2026-59817MedJul 9, 2026
    risk 0.27cvss 5.3epss 0.00

    Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or…

  • CVE-2026-7912MedMay 6, 2026
    risk 0.27cvss 4.2epss 0.00

    Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-32699MedMay 5, 2026
    risk 0.27cvss —epss 0.00

    FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass…

  • CVE-2026-2519MedApr 9, 2026
    risk 0.27cvss 5.3epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation…

  • CVE-2025-3743MedApr 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the…

  • CVE-2023-24373LowJun 3, 2024
    risk 0.24cvss 3.7epss 0.00

    External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

  • CVE-2020-1765LowJan 10, 2020
    risk 0.23cvss 3.5epss 0.01

    An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions;…