Detailedseverity: MediumDraft
CAPEC-387Navigation Remapping To Propagate Malicious Content
Abstraction
Detailed
Status
Draft
Severity
Medium
Description
An adversary manipulates either egress or ingress data from a client within an application framework in order to change the content of messages and thereby circumvent the expected application logic.
Metadata: detailed CAPEC pattern, status draft, severity medium. Underlying weaknesses: CWE-471, CWE-345, CWE-346, CWE-602, CWE-311. Related CAPEC pattern: [object Object].
Related weaknesses· 5
Related attack patterns· 1
Exploits5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Encryption of Sensitive Datacwe-311 | 100% | live |
| Weakness | Insufficient Verification of Data Authenticitycwe-345 | 100% | live |
| Weakness | Modification of Assumed-Immutable Data (MAID)cwe-471 | 100% | live |
| Weakness | Origin Validation Errorcwe-346 | 100% | live |
| Weakness | Client-Side Enforcement of Server-Side Securitycwe-602 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.