An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPre
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Inject
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults
Frequently Asked Questions
What is CWE-1321?
CWE-1321 (CWE-1321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1321?
There are 162 CVE records associated with CWE-1321 in our database. Of these, 27 are critical severity, 62 are high severity, and 52 are medium severity.
How can I protect against CWE-1321 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1321 using AI-powered security agents.
Detect CWE-1321 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1321 vulnerabilities across your infrastructure.
Get Started