CAPEC Definitions

    CAPEC Definitions / CAPEC-240

    CAPEC-240: Resource Injection

    An adversary exploits weaknesses in input validation by manipulating resource identifiers enabling the unintended modification or specification of a resource.

    Severity:High
    Possibility:High

    Extended Description

    No Extended Description.

    Mitigations

    Ensure all input content that is delivered to client is sanitized against an acceptable content specification.

    Perform input validation for all content.

    Enforce regular patching of software.

    Relationships with other CAPECs

    No related CAPECs found.

    Prerequisites

    The target application allows the user to both specify the identifier used to access a system resource. Through this permission, the user gains the capability to perform actions on that resource (e.g., overwrite the file)

    Related Weaknesses

    CWE-99: Improper Control of Resource Identifiers ('Resource Injection')