CWE-610

Externally Controlled Reference to a Resource in Another Sphere
AI Translation Available

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Status
draft
Abstraction
class

Common Consequences

confidentiality integrity access control
Impacts
read application data modify application data gain privileges or assume identity

Potential Mitigations