logo

Database

Description

The application allows extra parameters injection to HTTP communication protocol, this can cause unexpected behavior on the server.

Impact

- Make the application to read malicious parameters and have a wrong behavior. - Cause unexpected behaviors on the application.

Recommendation

Make validations to guarantee that the quantity of received parameters is equal to the expected parameters on the server.

Threat

Anonymous attacker from the Internet.

Expected Remediation Time

⏱️ 30 minutes.

Score

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

Attack vector

N

Attack complexity

L

Attack requirements

N

Privileges required

L

User interaction

N

Confidentiality (VC)

N

Integrity (VI)

H

Availability (VA)

N

Confidentiality (SC)

N

Integrity (SI)

N

Availability (SA)

N

Threat 4.0

Exploit maturity

X

Vector string

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N