CWE-610 — Externally Controlled Reference to a Resource in Another Sphere
CWE-610: Externally Controlled Reference to a Resource in Another Sphere
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Class |
| Status | Draft |
| Likelihood of exploit | — |
Description
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Common consequences
- Confidentiality, Integrity: Read Application Data, Modify Application Data
- Access Control: Gain Privileges or Assume Identity
Mitigations
(none listed)
References
- CWE page: https://cwe.mitre.org/data/definitions/610.html
- CWE list: https://cwe.mitre.org/data/index.html