Umbra Wiki weakness weakness/CWE-93
Back to wiki

CWE-93 — Improper Neutralization of CRLF Sequences ('CRLF Injection')

provenance: imported · CWE: CWE-93

CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Common consequences

  • Integrity: Modify Application Data

Mitigations

Implementation — Avoid using CRLF as a special sequence.

Implementation — Appropriately filter or quote CRLF sequences in user-controlled input.

References

  • CWE page: https://cwe.mitre.org/data/definitions/93.html
  • CWE list: https://cwe.mitre.org/data/index.html