VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 77 of 350
  • CVE-2023-42833HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.

  • CVE-2023-51784CriJan 3, 2024
    risk 0.57cvss 9.8epss 0.02

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it.…

  • CVE-2023-46987HigDec 28, 2023
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.

  • CVE-2023-50723CriDec 15, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping in the code for displaying…

  • CVE-2023-43364CriDec 12, 2023
    risk 0.57cvss 9.8epss 0.03

    main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

  • CVE-2023-42890HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.03

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.

  • CVE-2023-5500HigDec 11, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device.

  • CVE-2023-5762HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.02

    The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.

  • CVE-2023-48887CriDec 1, 2023
    risk 0.57cvss 9.8epss 0.02

    A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.

  • CVE-2023-47444HigNov 15, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

  • CVE-2023-36437HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure DevOps Server Remote Code Execution Vulnerability

  • CVE-2023-46243CriNov 7, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. A…

  • CVE-2023-46947HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Subrion 4.2.1 has a remote command execution vulnerability in the backend.

  • CVE-2023-42658HigOct 31, 2023
    risk 0.57cvss 8.8epss 0.00

    Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

  • CVE-2023-46816HigOct 27, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing…

  • CVE-2023-37909CriOct 25, 2023
    risk 0.57cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arbitrary script macros including Groovy…

  • CVE-2023-46055HigOct 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function to the "thingnario Logger Maintenance Webpage" endpoint.

  • CVE-2023-45312HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.02

    In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.

  • CVE-2023-44846HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.

  • CVE-2023-45311CriOct 6, 2023
    risk 0.57cvss 9.8epss 0.02

    fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was…