BaseDraft

CWE-348Use of Less Trusted Source

Category: other

Description

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Common consequences· 1

  • Access Control — Bypass Protection Mechanism, Gain Privileges or Assume Identity
    An attacker could utilize the untrusted data source to bypass protection mechanisms and gain access to sensitive data.

Related CAPEC attack patterns· 5

CAPEC-141CAPEC-142CAPEC-73CAPEC-76CAPEC-85

References

  1. https://cwe.mitre.org/data/definitions/348.html

Exploits (incoming)5

TypeTargetConfidenceTier
AttackPatternDNS Cache Poisoningcapec-142100%live
AttackPatternManipulating Web Input to File System Callscapec-76100%live
AttackPatternCache Poisoningcapec-141100%live
AttackPatternUser-Controlled Filenamecapec-73100%live
AttackPatternAJAX Footprintingcapec-85100%live

(incoming)5

TypeTargetConfidenceTier
VulnerabilityCVE-2025-48865cve-2025-488650%live
VulnerabilityCVE-2025-55292cve-2025-552920%live
VulnerabilityCVE-2025-59951cve-2025-599510%live
VulnerabilityCVE-2025-69240cve-2025-692400%live
VulnerabilityCVE-2026-44183cve-2026-441830%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Reliance on Insufficiently Trustworthy Component
CWE
Insufficient Verification of Data Authenticity
CWE
Insufficiently Protected Credentials
CWE
Weak Authentication
CWE
Reliance on Untrusted Inputs in a Security Decision
CWE
Exposure of Sensitive Information to an Unauthorized Actor
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.