CWE-472 - CERT CVE

CWE-472 - External Control of Assumed-Immutable Web Parameter

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

CAPEC ID Naziv
CAPEC-146 XML Schema Poisoning
CAPEC-226 Session Credential Falsification through Manipulation
CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies
CAPEC-39 Manipulating Opaque Client-based Data Tokens