Description
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. A low-privileged user can modify the parameters and potentially manipulate account-level privileges.
Problem types
CWE-472 External Control of Assumed-Immutable Web Parameter
Product status
20200630 (custom) before 20241112
20200630 (custom) before 20241112
20220413 (custom) before 20240919
20230308 (custom) before 20250827
Credits
Joel Aviad Ossi of WebSec B.V reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-022-05