CWE-621: Variable Extraction Error

low-risk

The product uses external input to determine the names of variables into which information is extracted, without verifying that the names of the specified variables are valid. This could cause the program to overwrite unintended variables.

Abstraction: Variant

Common Consequences

Integrity Modify Application Data

Real-World Examples (1)

CVE CVSS EPSS KEV
CVE-2018-6334 9.8 0.6%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal