CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

138 vulnerabilities with CWE-915
CVE-2022-48359 HIGH
Huawei EMUI and HarmonyOS - Arbitrary Disk Modification via Recovery Mode
CVSS 7.5
CVE-2022-43441 HIGH
Ghost sqlite3 5.0.0-5.1.1 - Remote Code Execution via Statement Bindings
CVSS 8.1
CVE-2022-4068 MEDIUM
LibreNMS <= 22.10.0 - Account Re-enablement and XSS
CVSS 5.4
CVE-2022-2625 HIGH
PostgreSQL - Arbitrary Code Execution via Extension Schema Object Hijacking
CVSS 8.0
CVE-2022-31106 HIGH
Underscore.deep <0.5.3 - Prototype Pollution
CVSS 8.3
CVE-2022-24802 HIGH
deepmerge-ts < 4.0.2 - Prototype Pollution via defaultMergeRecords Function
CVSS 8.1
CVE-2021-32811 HIGH
Zope 4.0-4.6.2 and 5.0-5.2 - Remote Code Execution via Python Script Object Modification
CVSS 7.5
CVE-2021-32807 MEDIUM
AccessControl 4.0-4.2 - Remote Code Execution via String Formatter Override
CVSS 4.4
CVE-2021-21368 MEDIUM
msgpack5 < 3.6.1 - Prototype Poisoning via __proto__ Key Decoding
CVSS 6.7
CVE-2021-21297 HIGH
Node-Red <1.2.8 - Prototype Pollution
CVSS 7.7
CVE-2021-21304 HIGH
Dynamoose <2.7.0 - Prototype Pollution
CVSS 7.2
CVE-2020-11066 HIGH
TYPO3 CMS >=9.0.0 <9.5.17, >=10.0.0 <10.4.2 - Code Injection
CVSS 8.7
CVE-2019-9057 HIGH
CMS Made Simple < 2.2.8 - Authenticated Object Injection via FilePicker Module
CVSS 8.8
Details
Vulnerabilities 138