VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,044)

page 134 of 353
  • CVE-2022-46333HigDec 6, 2022
    risk 0.47cvss 7.2epss 0.01

    The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below.

  • CVE-2022-3696HigDec 1, 2022
    risk 0.47cvss 7.2epss 0.01

    A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2022-3384HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.03

    The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP…

  • CVE-2022-3383HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.03

    The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for…

  • CVE-2022-41158HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.02

    Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code.

  • CVE-2022-39833HigNov 23, 2022
    risk 0.47cvss 7.2epss 0.03

    FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.

  • CVE-2022-3418HigNov 7, 2022
    risk 0.47cvss 7.2epss 0.01

    The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files

  • CVE-2022-3394HigOct 25, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only…

  • CVE-2022-41534HigOct 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-25812HigAug 22, 2022
    risk 0.47cvss 7.2epss 0.02

    The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE

  • CVE-2022-36216HigAug 17, 2022
    risk 0.47cvss 7.2epss 0.02

    DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.

  • CVE-2022-35772HigAug 9, 2022
    risk 0.47cvss 7.2epss 0.02

    Azure Site Recovery Remote Code Execution Vulnerability

  • CVE-2022-34625HigAug 2, 2022
    risk 0.47cvss 7.2epss 0.03

    Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.

  • CVE-2015-3173HigJul 6, 2022
    risk 0.47cvss 7.2epss 0.03

    custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution.

  • CVE-2022-24828HigApr 13, 2022
    risk 0.47cvss 8.3epss 0.02

    Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on…

  • CVE-2021-43097HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.02

    A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.

  • CVE-2021-43944HigMar 8, 2022
    risk 0.47cvss 7.2epss 0.02

    This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute…

  • CVE-2021-44238HigMar 1, 2022
    risk 0.47cvss 7.2epss 0.02

    AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,

  • CVE-2021-46118HigJan 26, 2022
    risk 0.47cvss 7.2epss 0.02

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

  • CVE-2021-46117HigJan 26, 2022
    risk 0.47cvss 7.2epss 0.03

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.