CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 313 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2259 | Hig | 0.00 | 7.2 | 0.01 | Apr 24, 2023 | Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. | ||
| CVE-2022-4455 | Low | 0.00 | 3.5 | 0.01 | Dec 13, 2022 | A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is… | ||
| CVE-2022-46166 | Hig | 0.00 | 8.0 | 0.01 | Dec 9, 2022 | Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are… | ||
| CVE-2022-43279 | Hig | 0.00 | 7.2 | 0.01 | Nov 15, 2022 | LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php. | ||
| CVE-2022-41882 | Med | 0.00 | 6.6 | 0.00 | Nov 11, 2022 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a malicious file share and has it synced locally or the virtual filesystem enabled and clicked a nc://open/ link it will open the default… | ||
| CVE-2022-40314 | Cri | 0.00 | 9.8 | 0.02 | Sep 30, 2022 | A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. | ||
| CVE-2022-40497 | Hig | 0.00 | 8.8 | 0.01 | Sep 28, 2022 | Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint. | ||
| CVE-2022-2636 | Hig | 0.00 | 8.5 | 0.01 | Aug 5, 2022 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||
| CVE-2022-2014 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Code Injection in GitHub repository jgraph/drawio prior to 19.0.2. | ||
| CVE-2021-42651 | Hig | 0.00 | 8.8 | 0.02 | May 11, 2022 | A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/. | ||
| CVE-2022-1575 | Cri | 0.00 | 9.6 | 0.02 | May 5, 2022 | Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app. | ||
| CVE-2022-24735 | Low | 0.00 | 3.9 | 0.02 | Apr 27, 2022 | Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another… | ||
| CVE-2022-24780 | Hig | 0.00 | 8.8 | 0.05 | Apr 5, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue… | ||
| CVE-2021-43811 | Hig | 0.00 | 7.8 | 0.02 | Dec 8, 2021 | Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in… | ||
| CVE-2021-3725 | Hig | 0.00 | 7.5 | 0.01 | Nov 30, 2021 | Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name,… | ||
| CVE-2021-40348 | Hig | 0.00 | 8.8 | 0.02 | Nov 1, 2021 | Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to… | ||
| CVE-2021-42139 | Cri | 0.00 | 9.8 | 0.02 | Oct 11, 2021 | Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. | ||
| CVE-2021-32749 | Med | 0.00 | 6.1 | 0.04 | Jul 16, 2021 | fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from… | ||
| CVE-2019-14827 | Med | 0.00 | 6.1 | 0.01 | May 17, 2021 | A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another… | ||
| CVE-2021-29502 | Hig | 0.00 | 7.3 | 0.01 | May 10, 2021 | WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations by setting up a specific template which is not properly sanitized. The problem has been patched in version 1.3.18. Users should… |
- risk 0.00cvss 7.2epss 0.01
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
- risk 0.00cvss 3.5epss 0.01
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is…
- risk 0.00cvss 8.0epss 0.01
Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are…
- risk 0.00cvss 7.2epss 0.01
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
- risk 0.00cvss 6.6epss 0.00
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a malicious file share and has it synced locally or the virtual filesystem enabled and clicked a nc://open/ link it will open the default…
- risk 0.00cvss 9.8epss 0.02
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
- risk 0.00cvss 8.8epss 0.01
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.
- risk 0.00cvss 8.5epss 0.01
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- risk 0.00cvss 5.4epss 0.01
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
- risk 0.00cvss 8.8epss 0.02
A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.
- risk 0.00cvss 9.6epss 0.02
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
- risk 0.00cvss 3.9epss 0.02
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another…
- risk 0.00cvss 8.8epss 0.05
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue…
- risk 0.00cvss 7.8epss 0.02
Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in…
- risk 0.00cvss 7.5epss 0.01
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name,…
- risk 0.00cvss 8.8epss 0.02
Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to…
- risk 0.00cvss 9.8epss 0.02
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
- risk 0.00cvss 6.1epss 0.04
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from…
- risk 0.00cvss 6.1epss 0.01
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another…
- risk 0.00cvss 7.3epss 0.01
WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations by setting up a specific template which is not properly sanitized. The problem has been patched in version 1.3.18. Users should…