VariantDraft

CWE-554ASP.NET Misconfiguration: Not Using Input Validation Framework

Category: config

Description

The ASP.NET application does not use an input validation framework.

Common consequences· 1

  • Integrity — Unexpected State
    Unchecked input leads to cross-site scripting, process control, and SQL injection vulnerabilities, among others.

Potential mitigations· 1

  • [Architecture and Design]

References

  1. https://cwe.mitre.org/data/definitions/554.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
ASP.NET Misconfiguration: Improper Model Validation
CWE
ASP.NET Misconfiguration: Missing Custom Error Page
CWE
Struts: Validator Turned Off
CWE
Improper Use of Validation Framework
CWE
Struts: Plug-in Framework not in Use
CWE
ASP.NET Misconfiguration: Password in Configuration File
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.