VYPR

CWE-707

Improper Neutralization

PillarIncomplete

Description

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-250 · CAPEC-276 · CAPEC-277 · CAPEC-278 · CAPEC-279 · CAPEC-3 · CAPEC-43 · CAPEC-468 · CAPEC-52 · CAPEC-53 · CAPEC-64 · CAPEC-7 · CAPEC-78 · CAPEC-79 · CAPEC-83 · CAPEC-84

CVEs mapped to this weakness (253)

page 8 of 13
  • CVE-2022-4350LowDec 8, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit…

  • CVE-2022-4348LowDec 8, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown functionality of the component JSON Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been…

  • CVE-2022-4347LowDec 8, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely.…

  • CVE-2022-4341LowDec 7, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in csliuwy coder-chain_gdut and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /back/index.php/user/User/?1. The manipulation leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2022-4279LowDec 3, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Human Resource Management System 1.0. Affected is an unknown function of the file /hrm/employeeview.php. The manipulation of the argument search leads to cross site scripting. It is possible to launch the…

  • CVE-2022-4253LowDec 1, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnerability affects the function builtin_echo of the file customer.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The…

  • CVE-2022-4252LowDec 1, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function builtin_echo of the file categories.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2022-4250LowDec 1, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerability is an unknown functionality of the file booking.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched…

  • CVE-2022-4249LowDec 1, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown function of the component POST Request Handler. The manipulation of the argument ORDER_ID leads to cross site scripting. It is possible to launch the attack…

  • CVE-2022-4234LowNov 30, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affects the function builtin_echo of the file youthappam/brand.php. The manipulation of the argument brand_name leads to cross site scripting. The attack may be…

  • CVE-2022-4091LowNov 25, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function query of the file food.php. The manipulation of the argument product_name leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2022-3971MedNov 13, 2022
    risk 0.23cvss 4.6epss 0.01

    A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version…

  • CVE-2022-3949LowNov 11, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in Sourcecodester Simple Cashiering System. This issue affects some unknown processing of the component User Account Handler. The manipulation of the argument fullname leads to cross site scripting. The attack…

  • CVE-2022-3943LowNov 11, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ForU CMS. It has been classified as problematic. Affected is an unknown function of the file cms_chip.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2022-3803LowNov 1, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in eolinker apinto-dashboard and classified as problematic. This issue affects some unknown processing of the file /api/discoveries/. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2022-3716LowOct 27, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name/Middle Name/Last Name leads…

  • CVE-2022-3673LowOct 26, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in SourceCodester Sanitization Management System 1.0. Affected is an unknown function of the file /php-sms/classes/Master.php. The manipulation of the argument message leads to cross site scripting. It is possible…

  • CVE-2022-3672LowOct 26, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in SourceCodester Sanitization Management System 1.0. This issue affects some unknown processing of the file /php-sms/classes/SystemSettings.php. The manipulation of the argument name/shortname leads to cross…

  • CVE-2022-3587LowOct 18, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component My Account. The manipulation of the argument First Name leads to cross site…

  • CVE-2022-3505LowOct 14, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is possible to launch the…