VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 162 of 353
  • CVE-2024-25202MedFeb 28, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

  • CVE-2023-50808MedFeb 13, 2024
    risk 0.40cvss 6.1epss 0.00

    Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.

  • CVE-2024-24396MedFeb 5, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.

  • CVE-2023-40809MedNov 18, 2023
    risk 0.40cvss 6.1epss 0.00

    OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.

  • CVE-2023-39956MedSep 6, 2023
    risk 0.40cvss 6.1epss 0.01

    Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if the following conditions are met: 1. The…

  • CVE-2023-3551HigJul 8, 2023
    risk 0.40cvss 7.2epss 0.01

    Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2023-30179HigJun 13, 2023
    risk 0.40cvss 7.2epss 0.02

    CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this…

  • CVE-2022-35944MedOct 13, 2022
    risk 0.40cvss 6.2epss 0.01

    October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has…

  • CVE-2022-38193MedAug 16, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.

  • CVE-2021-21237HigJan 15, 2021
    risk 0.40cvss 7.2epss 0.00

    Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a malicious repository with a git.bat or git.exe file in the current directory, that program would be executed, permitting the attacker to execute arbitrary code. This does…

  • CVE-2019-19089MedApr 2, 2020
    risk 0.40cvss 6.1epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code…

  • CVE-2019-13714MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.

  • CVE-2019-7942HigAug 2, 2019
    risk 0.40cvss 7.2epss 0.02

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create or edit a product can execute arbitrary code via malicious XML layout updates.

  • CVE-2019-7932HigAug 2, 2019
    risk 0.40cvss 7.2epss 0.02

    A remote code execution vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create sitemaps can…

  • CVE-2019-7903HigAug 2, 2019
    risk 0.40cvss 7.2epss 0.02

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to email templates can execute arbitrary code by previewing a malicious template.

  • CVE-2019-12844MedJul 3, 2019
    risk 0.40cvss 6.1epss 0.01

    A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

  • CVE-2019-12843MedJul 3, 2019
    risk 0.40cvss 6.1epss 0.01

    A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.

  • CVE-2018-19641MedMar 27, 2019
    risk 0.40cvss 6.1epss 0.01

    Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

  • CVE-2019-4038MedFeb 4, 2019
    risk 0.40cvss 6.2epss 0.00

    IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.

  • CVE-2016-10548MedMay 31, 2018
    risk 0.40cvss 6.1epss 0.01

    Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function.