VYPR

CWE-75

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

ClassDraft

Description

The product does not adequately filter user-controlled input for special elements with control implications.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-81 · CAPEC-93

CVEs mapped to this weakness (6)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-31908Cri0.599.10.00Apr 14, 2026Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.
CVE-2024-37779Hig0.588.80.05Sep 23, 2024WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
CVE-2024-23274Hig0.517.80.00Mar 8, 2024An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
CVE-2024-23268Hig0.517.80.00Mar 8, 2024An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
CVE-2024-24257Hig0.497.50.00Jul 26, 2024An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.
CVE-2024-21503Med0.275.30.00Mar 19, 2024Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service. Exploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.