CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

ID CWE-917
Abstraction Base
Structure Simple
Status Incomplete
Number of CVEs 165
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.

Modes of Introduction

Phase Note
Architecture and Design
Implementation

Applicable Platforms

Type Class Name Prevalence
Language Java

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Class Simple Draft
CWE-1000 Research Concepts Draft CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine Base Simple Incomplete
CWE-1003 Weaknesses for Simplified Mapping of Published Vulnerabilities Incomplete CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Class Simple Incomplete
CWE-1305 CISQ Quality Measures (2020) Incomplete CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Class Simple Draft
CWE-1340 CISQ Data Protection Measures Incomplete CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Class Simple Draft

CVEs Published

CVSS Severity

CVSS Severity - By Year

CVSS Base Score

# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...
Loading...