VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,047)

page 174 of 353
  • CVE-2023-6601MedJan 6, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.

  • CVE-2024-37773MedDec 16, 2024
    risk 0.31cvss 4.8epss 0.00

    An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.

  • CVE-2024-8523MedSep 7, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. The manipulation of the argument data leads to code…

  • CVE-2024-43922MedAug 29, 2024
    risk 0.31cvss 4.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.

  • CVE-2024-7899MedAug 17, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in InnoCMS 0.3.1. This issue affects some unknown processing of the file /panel/pages/1/edit of the component Backend. The manipulation leads to code injection. The attack may be initiated remotely. The exploit…

  • CVE-2024-6947MedJul 21, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been rated as critical. This issue affects the function replaceContent of the file app/Core/Support/ContentParser.php of the component Notification Handler. The manipulation leads to code injection. The attack may be…

  • CVE-2024-6946MedJul 21, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been declared as critical. This vulnerability affects unknown code of the file /admin/pages/list. The manipulation of the argument blocks leads to code injection. The attack can be initiated remotely. The exploit has…

  • CVE-2024-6940MedJul 21, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2023-44853MedApr 12, 2024
    risk 0.31cvss 4.8epss 0.00

    \An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_219C4 function in the acu_web file.

  • CVE-2024-27476MedApr 10, 2024
    risk 0.31cvss 4.7epss 0.01

    Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.

  • CVE-2024-28005MedMar 28, 2024
    risk 0.31cvss 4.7epss 0.00

    Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N,…

  • CVE-2024-2497MedMar 15, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The…

  • CVE-2023-6886MedDec 17, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been…

  • CVE-2023-5512MedDec 15, 2023
    risk 0.31cvss 4.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading…

  • CVE-2023-5226MedDec 1, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted…

  • CVE-2023-6188MedNov 17, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2023-5221MedSep 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/index.php. The manipulation of the argument db_name leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2023-3401MedAug 2, 2023
    risk 0.31cvss 4.8epss 0.01

    An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories…

  • CVE-2023-1482MedMar 18, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/local.html?type=addon of the component External Plugin Handler. The manipulation leads to code injection. It is possible to…

  • CVE-2022-24441MedNov 30, 2022
    risk 0.31cvss 5.8epss 0.01

    The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges…