CAPEC-261: Fuzzing for garnering other adjacent user/sensitive data

An adversary who is authorized to send queries to a target sends variants of expected queries in the hope that these modified queries might return information (directly or indirectly through error logs) beyond what the expected set of queries should provide.

Severity
Medium
12
/ 100
low-risk
Active Threat 10/50 · Low
Exploit Availability 2/50 · Minimal