5. of Elevation of Privilege II
An attacker can force data through different validation paths, which give different results.
Threat |
|
Your site is multilingual and implementations for each language may differ slightly. An attacker can change the default language in their browser, causing a change in flow so that they can take advantage of some missing validation. |
|
CAPEC |
CAPEC-554 – Functionality bypass CAPEC-140 – Bypassing of intermediate forms in multiple-form sets CAPEC-29 – Leveraging time-of-check and time-of-use (TOCTOU) race conditions |
ASVS |
1.11.2 – Verify thread safety 1.11.3 – Check for TOCTOU issues 11.1.1 – Verify application flow is enforced |
CWE |
... |