DetailedDraft
CAPEC-500WebView Injection
Abstraction
Detailed
Status
Draft
Description
An adversary, through a previously installed malicious application, injects code into the context of a web page displayed by a WebView component. Through the injected code, an adversary is able to manipulate the DOM tree and cookies of the page, expose sensitive information, and can launch attacks against the web application from within the web page.
Related weaknesses· 2
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Verification of Source of a Communication Channelcwe-940 | 100% | live |
| Weakness | Exposed Dangerous Method or Functioncwe-749 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.