VYPR

CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

ClassDraftLikelihood: High

Description

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-240 · CAPEC-75

CVEs mapped to this weakness (58)

page 2 of 3
  • CVE-2025-1645MedFeb 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in Benner Connecta 1.0.5330. Affected by this vulnerability is an unknown functionality of the file /Usuarios/Usuario/EditarLogado/. The manipulation of the argument Handle leads to improper control of resource identifiers. The…

  • CVE-2024-4817MedMay 14, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulation of the argument id leads to improper…

  • CVE-2024-4294MedApr 27, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulation of the argument editid leads to…

  • CVE-2023-2980MedMay 30, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit…

  • CVE-2019-1860MedMay 16, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center. The vulnerability is due to…

  • CVE-2026-9438MedMay 25, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file courseDel.php. The manipulation of the argument ID results in improper control of resource identifiers. The attack may be…

  • CVE-2025-9264MedAug 21, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper…

  • CVE-2024-7437MedAug 3, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to…

  • CVE-2022-3774MedOct 31, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource…

  • CVE-2016-8615MedAug 1, 2018
    risk 0.35cvss 5.3epss 0.05

    A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.

  • CVE-2026-5414MedApr 2, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack…

  • CVE-2025-9619MedAug 29, 2025
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing manipulation results in improper control of resource identifiers. It is possible to initiate the…

  • CVE-2023-6604MedJan 6, 2025
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

  • CVE-2023-6602MedDec 31, 2024
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.

  • CVE-2023-6601MedJan 6, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.

  • CVE-2026-12207MedJun 15, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medical\port\rest\controllers\PatientController.php of the component HTTP REST API. The manipulation of…

  • CVE-2026-10624MedJun 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument employeeid leads to improper control of…

  • CVE-2026-5031MedMar 29, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the argument ID results in improper control of resource identifiers. The attack can…

  • CVE-2025-12270MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignment_id}/tasks/{task_id}/sub_file of the component Student Assignment Submission Handler. This…

  • CVE-2025-9263MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of…