VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,044)

page 140 of 353
  • CVE-2024-7627HigSep 5, 2024
    risk 0.46cvss 8.1epss 0.03

    The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for…

  • CVE-2024-22169HigAug 2, 2024
    risk 0.46cvss epss 0.00

    WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit…

  • CVE-2024-6655HigJul 16, 2024
    risk 0.46cvss 7.0epss 0.00

    A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.

  • CVE-2024-36120HigMay 31, 2024
    risk 0.46cvss 8.1epss 0.00

    javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised to update. Users unable to upgrade…

  • CVE-2024-33443HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.01

    An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.

  • CVE-2024-32492HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.

  • CVE-2023-50447HigJan 19, 2024
    risk 0.46cvss 8.1epss 0.02

    Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

  • CVE-2023-5623HigOct 26, 2023
    risk 0.46cvss 7.0epss 0.00

    NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location

  • CVE-2023-28796HigOct 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

  • CVE-2023-26436HigJun 20, 2023
    risk 0.46cvss 7.1epss 0.01

    Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being…

  • CVE-2023-0788HigFeb 12, 2023
    risk 0.46cvss 8.1epss 0.01

    Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2022-25967HigJan 30, 2023
    risk 0.46cvss 8.1epss 0.02

    Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with…

  • CVE-2022-25860HigJan 26, 2023
    risk 0.46cvss 8.1epss 0.03

    Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of…

  • CVE-2022-24439HigDec 6, 2022
    risk 0.46cvss 8.1epss 0.05

    All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes…

  • CVE-2022-39327HigOct 25, 2022
    risk 0.46cvss 8.1epss 0.03

    Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an…

  • CVE-2022-25760HigMar 17, 2022
    risk 0.46cvss 7.1epss 0.02

    All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible…

  • CVE-2021-23406HigAug 24, 2021
    risk 0.46cvss 8.1epss 0.03

    This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

  • CVE-2021-34551HigJun 16, 2021
    risk 0.46cvss 8.1epss 0.03

    PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.

  • CVE-2020-28502HigMar 5, 2021
    risk 0.46cvss 8.1epss 0.05

    This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

  • CVE-2020-7745HigOct 19, 2020
    risk 0.46cvss 7.1epss 0.03

    This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitrary code on a user device.