VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 255 of 274
  • CVE-2020-9495MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.08

    Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to…

  • CVE-2020-3246MedMay 6, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service. The vulnerability is due to insufficient validation of user input. An…

  • CVE-2019-15616MedFeb 4, 2020
    risk 0.28cvss 4.3epss 0.01

    Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

  • CVE-2019-11282MedOct 23, 2019
    risk 0.28cvss 4.3epss 0.01

    Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.

  • CVE-2019-11275MedOct 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can…

  • CVE-2019-5977MedSep 12, 2019
    risk 0.28cvss 4.3epss 0.01

    Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.

  • CVE-2018-20898MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

  • CVE-2019-1680MedFeb 7, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could exploit this vulnerability by convincing a targeted user to…

  • CVE-2017-5246MedJul 18, 2017
    risk 0.28cvss 4.3epss 0.01

    Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other…

  • CVE-2016-8720MedApr 13, 2017
    risk 0.28cvss 4.3epss 0.01

    An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be copied in to Location…

  • CVE-2016-5013MedJan 20, 2017
    risk 0.28cvss 5.4epss 0.01

    In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.

  • CVE-2015-8748MedFeb 3, 2016
    risk 0.28cvss 5.3epss 0.02

    Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".

  • CVE-2026-47256MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled…

  • CVE-2026-86252MedSep 6, 2026
    risk 0.27cvss 5.3epss 0.00

    h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into…

  • CVE-2026-63621MedAug 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers. In…

  • CVE-2026-49099MedJul 6, 2026
    risk 0.27cvss 5.3epss 0.01

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The camel-salesforce producer resolves its operation parameters - the SOQL…

  • CVE-2026-49098MedJul 6, 2026
    risk 0.27cvss 5.3epss 0.01

    Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Kafka Component. The camel-kafka producer can override its configured target topic at runtime from the…

  • CVE-2026-11487MedJun 8, 2026
    risk 0.27cvss 5.3epss 0.01

    A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on…

  • CVE-2026-7580MedMay 1, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading…

  • CVE-2023-7333MedJan 7, 2026
    risk 0.27cvss 5.3epss 0.00

    A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes sql injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to…