CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

138 vulnerabilities with CWE-915
CVE-2025-68109 CRITICAL
ChurchCRM < 6.5.3 - Remote Code Execution via Database Restore File Upload
CVSS 9.1
CVE-2025-66451 MEDIUM
LibreChat < 0.8.1 - Improperly Controlled Modification of Dynamically-Determined Object Attributes via PATCH Endpoint
CVSS 6.5
CVE-2025-9315 MEDIUM
MXsecurity Series - Unauthenticated RCE
CVE-2025-66400 MEDIUM
mdast-util-to-hast <13.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-13081 MEDIUM
Drupal 8.0.0-10.4.8, 10.5.0-10.5.5, 11.0.0-11.1.8, 11.2.0-11.2.7 - Object Injection
CVSS 5.9
CVE-2025-52656 HIGH
HCL MyXalytics: 6.6 - Info Disclosure
CVSS 7.6
CVE-2025-7104 HIGH
danny-avila/librechat - Mass Assignment
CVSS 7.5
CVE-2025-58367 CRITICAL
deepdiff 5.0.0-8.6.0 - Remote Code Execution via Delta Class Pollution and Pickle Deserialization
CVE-2025-6107 LOW
comfyanonymous comfyui <0.3.40 - Code Injection
CVSS 3.1
CVE-2025-49597 LOW
goodby-csv < 1.4.3 - Gadget Chain for Remote Code Execution via Insecure Deserialization
CVSS 3.9
CVE-2025-31674 HIGH
Drupal Drupal core <10.3.13-11.1.3 - Object Injection
CVSS 7.5
CVE-2025-30358 HIGH
Mesop < 0.14.1 - Class Pollution leading to Denial of Service and Identity Confusion
CVSS 8.1
CVE-2025-2304 CRITICAL
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
CVE-2025-24370 CRITICAL
django-unicorn < 0.62.0 - Python Class Pollution via set_property_value
CVE-2024-57708 MEDIUM
OneTrust SDK 6.33.0 - Denial of Service via Prototype Pollution
CVSS 5.7
CVE-2024-10359 MEDIUM
danny-avila/librechat <0.7.5-rc2 - Code Injection
CVSS 4.6
CVE-2024-55638 CRITICAL
Drupal 7.0-7.101, 8.8.0-10.2.10, 10.3.0-10.3.8 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2024-55637 CRITICAL
Drupal 8.0.0-10.2.10 10.3.0-10.3.8 11.0.0-11.0.7 - Object Injection via Insecure Deserialization
CVSS 9.8
CVE-2024-55636 CRITICAL
Drupal 8.0.0-10.2.10 10.3.0-10.3.8 11.0.0-11.0.7 - Object Injection via Insecure Deserialization
CVSS 9.8
CVE-2024-5452 CRITICAL
pytorch_lightning < 2.3.3 - Remote Code Execution via Deepdiff Delta Dunder Attribute Bypass
CVSS 9.8
CVE-2024-0404 CRITICAL
Mintplex-Labs Anything-LLM - Privilege Escalation
CVSS 9.1
CVE-2024-3283 HIGH
AnythingLLM < 1.0.0 - Authenticated Privilege Escalation via Mass Assignment in Admin System Preferences
CVSS 7.2
CVE-2023-39983 MEDIUM
MXsecurity <1.0.1 - Info Disclosure
CVSS 5.3
CVE-2023-32079 HIGH
Netmaker <0.17.1 and 0.18.6 - Privilege Escalation
CVSS 8.8
CVE-2023-0574 MEDIUM
YugabyteDB Managed 2.0.0.0-2.13.0.0 - Server-Side Request Forgery
CVSS 6.8
Details
Vulnerabilities 138