VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 31 of 274
  • CVE-2024-36420HigJul 1, 2024
    risk 0.49cvss 7.5epss 0.02

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No…

  • CVE-2024-35059HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

  • CVE-2023-4818HigJan 15, 2024
    risk 0.49cvss 7.6epss 0.01

    PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

  • CVE-2023-44109HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-38609HigJul 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Privacy preferences.

  • CVE-2023-28598HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.

  • CVE-2023-23749HigJan 17, 2023
    risk 0.49cvss 7.5epss 0.01

    The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

  • CVE-2021-36913HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.

  • CVE-2022-28345HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash character in the URL. This technique allows a remote unauthenticated attacker to send legitimate looking…

  • CVE-2022-0391HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.08

    A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path.…

  • CVE-2020-12965HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.02

    When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.

  • CVE-2021-24948HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts

  • CVE-2021-32499HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.

  • CVE-2021-37262HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.01

    JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

  • CVE-2021-37033HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-37933HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logic of an LDAP query and bypass authentication. The vulnerability is due to insufficient server-side validation of the email…

  • CVE-2021-38371HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.02

    The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

  • CVE-2020-23148HigAug 9, 2021
    risk 0.49cvss 7.5epss 0.02

    The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.

  • CVE-2021-32558HigJul 30, 2021
    risk 0.49cvss 7.5epss 0.09

    An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.

  • CVE-2021-29084HigJun 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via…