Queen of Elevation of Privilege I
You include user-generated content within your page, possibly including the content of random URLs.
Threat |
|
Perhaps you offer a portal where users can showcase their web templates, graphic templates, or office templates and allow them to link directly to the files on their site. An attacker could make use of the trust users have in your site to deliver their malware. |
|
CAPEC |
CAPEC-17 – Using malicious files CAPEC-23 – File content injection |
ASVS |
1.12.2 – Ensure files are vetted so you don’t serve up malicious code to other users |
CWE |
CWE-434 – Unrestricted upload of file with dangerous type |