VYPR

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

BaseIncomplete

Description

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (230)

page 3 of 12
  • CVE-2020-28271CriNov 12, 2020
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28270CriNov 12, 2020
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-7720CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.03

    The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

  • CVE-2020-7719CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.03

    Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

  • CVE-2020-7708CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

  • CVE-2020-7707CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

  • CVE-2020-7706CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.

  • CVE-2020-7701CriAug 14, 2020
    risk 0.57cvss 9.8epss 0.02

    madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

  • CVE-2020-11066HigMay 14, 2020
    risk 0.57cvss 8.7epss 0.01

    In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering…

  • CVE-2019-14379CriJul 29, 2019
    risk 0.57cvss 9.8epss 0.08

    SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

  • CVE-2019-9057HigMar 26, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.

  • CVE-2018-19296HigNov 16, 2018
    risk 0.57cvss 8.8epss 0.02

    PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

  • CVE-2021-23452HigOct 20, 2021
    risk 0.56cvss 8.6epss 0.02

    This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.

  • CVE-2026-71473HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the…

  • CVE-2026-46441CriJun 8, 2026
    risk 0.55cvss 9.6epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties…

  • CVE-2026-42861CriJun 8, 2026
    risk 0.55cvss 9.6epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties…

  • CVE-2026-17095HigAug 12, 2026
    risk 0.54cvss 8.3epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.

  • CVE-2025-14341HigMay 7, 2026
    risk 0.54cvss 8.3epss 0.00

    Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from…

  • CVE-2025-2304CriMar 14, 2025
    risk 0.54cvss —epss 0.01

    A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to…

  • CVE-2026-55810HigJul 10, 2026
    risk 0.53cvss 8.1epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.