Standardseverity: MediumDraft

CAPEC-140Bypassing of Intermediate Forms in Multiple-Form Sets

Abstraction
Standard
Status
Draft
Severity
Medium

Description

Some web applications require users to submit information through an ordered sequence of web forms. This is often done if there is a very large amount of information being collected or if information on earlier forms is used to pre-populate fields or determine which additional information the application needs to collect. An attacker who knows the names of the various forms in the sequence may be able to explicitly type in the name of a later form and navigate to it without first going through the previous forms. This can result in incomplete collection of information, incorrect assumptions about the information submitted by the attacker, or other problems that can impair the functioning of the application.

Related weaknesses· 1

CWE-372

Related attack patterns· 1

CAPEC-74 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessIncomplete Internal State Distinctioncwe-372100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Forceful Browsing
CAPEC
Cross Site Request Forgery
CAPEC
Exploiting Multiple Input Interpretation Layers
CAPEC
XSS Through HTTP Query Strings
CAPEC
XPath Injection
CAPEC
XSS Through HTTP Headers
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.