VYPR

CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

ClassDraftLikelihood: High

Description

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-240 · CAPEC-75

CVEs mapped to this weakness (61)

page 4 of 4
  • CVE-2021-22879HigApr 14, 2021
    risk 0.00cvss 8.8epss 0.05

    Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.