CWE-707 对消息或数据结构的处理不恰当 类弱点 192 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-707属于数据验证类漏洞,指产品未确保结构化消息或数据在传输前后保持格式正确及满足安全属性。攻击者常利用此缺陷,通过构造畸形输入导致数据被错误解析,从而引发注入攻击或逻辑绕过。开发者应实施严格的输入输出验证机制,确保所有结构化数据在读写前经过规范化处理,以消除格式异常带来的安全风险。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-4247 | Movie Ticket Booking System 安全漏洞 — Movie Ticket Booking System | 6.3 | Medium | 2022-12-01 |
| CVE-2022-4248 | Movie Ticket Booking System 安全漏洞 — Movie Ticket Booking System | 5.0 | Medium | 2022-12-01 |
| CVE-2022-4249 | Movie Ticket Booking System 跨站脚本漏洞 — Movie Ticket Booking System | 3.5 | Low | 2022-12-01 |
| CVE-2022-4250 | Movie Ticket Booking System 安全漏洞 — Movie Ticket Booking System | 3.5 | Low | 2022-12-01 |
| CVE-2022-4251 | Movie Ticket Booking System 安全漏洞 — Movie Ticket Booking System | 2.4 | Low | 2022-12-01 |
| CVE-2022-4252 | Canteen Management System 安全漏洞 — Canteen Management System | 3.5 | Low | 2022-12-01 |
| CVE-2022-4253 | Canteen Management System 安全漏洞 — Canteen Management System | 3.5 | Low | 2022-12-01 |
| CVE-2022-4257 | C-DATA Web Management System 操作系统命令注入漏洞 — Web Management System | 6.3 | Medium | 2022-12-01 |
| CVE-2021-4242 | 多款Sapido产品操作系统命令注入漏洞 — BR270n | 6.3 | Medium | 2022-11-30 |
| CVE-2022-4222 | Canteen Management System SQL注入漏洞 — Canteen Management System | 5.0 | Medium | 2022-11-30 |
| CVE-2022-4233 | Event Registration System 跨站脚本漏洞 — Event Registration System | 2.4 | Low | 2022-11-30 |
| CVE-2022-4234 | Canteen Management System 安全漏洞 — Canteen Management System | 3.5 | Low | 2022-11-30 |
| CVE-2022-4091 | Canteen Management System 安全漏洞 — Canteen Management System | 3.5 | Low | 2022-11-25 |
| CVE-2022-4088 | Stock Management System SQL注入漏洞 — Stock Management System | 7.3 | High | 2022-11-24 |
| CVE-2022-4089 | Stock Management System 跨站脚本漏洞 — Stock Management System | 4.3 | Medium | 2022-11-24 |
| CVE-2022-4051 | Hostel searching project SQL注入漏洞 — Hostel Searching Project | 6.3 | Medium | 2022-11-17 |
| CVE-2022-4052 | Student Attendance Management System SQL注入漏洞 — Student Attendance Management System | 4.7 | Medium | 2022-11-17 |
| CVE-2022-4053 | Student Attendance Management System 跨站脚本漏洞 — Student Attendance Management System | 2.4 | Low | 2022-11-17 |
| CVE-2022-4011 | WordPress plugin Simple History 安全漏洞 — Simple History Plugin | 6.5 | Medium | 2022-11-16 |
| CVE-2022-4012 | Hospital Management System SQL注入漏洞 — Hospital Management Center | 6.3 | Medium | 2022-11-16 |
| CVE-2022-4015 | Sports-Club-Management-System 安全漏洞 — Sports Club Management System | 4.7 | Medium | 2022-11-16 |
| CVE-2022-3997 | MonikaBrzica scm 安全漏洞 — scm | 6.3 | Medium | 2022-11-15 |
| CVE-2022-3998 | MonikaBrzica scm 安全漏洞 — scm | 6.3 | Medium | 2022-11-15 |
| CVE-2022-3988 | Frappe Technologies Frappe 跨站脚本漏洞 — Frappe | 3.5 | Low | 2022-11-14 |
| CVE-2022-3992 | Sanitization Management System 跨站脚本漏洞 — Sanitization Management System | 2.4 | Low | 2022-11-14 |
| CVE-2022-3967 | Vesta Control Panel 参数注入漏洞 — Vesta Control Panel | 5.3 | Medium | 2022-11-13 |
| CVE-2022-3968 | emlog 跨站脚本漏洞 — emlog | 3.5 | Low | 2022-11-13 |
| CVE-2022-3971 | matrix-appservice-irc 安全漏洞 — matrix-appservice-irc | 4.6 | Medium | 2022-11-13 |
| CVE-2022-3972 | HMS-PHP 安全漏洞 — HMS-PHP | 7.3 | High | 2022-11-13 |
| CVE-2022-3973 | HMS-PHP 安全漏洞 — HMS-PHP | 7.3 | High | 2022-11-13 |
CWE-707(对消息或数据结构的处理不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 192 条 CVE 漏洞。