CWE Database
/

CWE-792

Back to CWE list

CWE-792

Incomplete Filtering of One or More Instances of Special Elements

Variant
Incomplete

Description

The product receives data from an upstream component, but does not completely filter one or more instances of special elements before sending it to a downstream component.

{"xhtml:p":["Incomplete filtering of this nature involves either:"],"xhtml:ul":[{"xhtml:li":["only filtering a single instance of a special element when more exist, or","not filtering all instances or all elements where multiple special elements exist."]}]}

Common Consequences

Scope

Integrity

Impact

Unexpected State

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now