CAPEC-261: Fuzzing for garnering other adjacent user/sensitive data
An adversary who is authorized to send queries to a target sends variants of expected queries in the hope that these modified queries might return information (directly or indirectly through error logs) beyond what the expected set of queries should provide.
Severity
Medium
12
/ 100
low-risk
Active Threat
10/50 · Low
Exploit Availability
2/50 · Minimal