CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

180 vulnerabilities with CWE-917
CVE-2019-7743 CRITICAL
Joomla! <3.9.3 - Code Injection
CVSS 9.8
CVE-2018-16621 HIGH
Sonatype Nexus Repository Manager <3.14 - Code Injection
CVSS 7.2
CVE-2018-12533 CRITICAL
JBoss RichFaces 3.1.0-3.3.4 - RCE
CVSS 9.8
CVE-2018-12532 CRITICAL
JBoss RichFaces <4.5.18 - RCE
CVSS 9.8
CVE-2010-1871 HIGH KEV
JBoss Seam 2 - RCE
CVSS 8.8
Details
Vulnerabilities 180