CWE-830

Inclusion of Web Functionality from an Untrusted Source

High

Description

The product includes web functionality (such as a web widget) from another domain, which causes it to operate within the domain of the product, potentially granting total access and control of the product to the untrusted source.

Potential Impact

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-830 vulnerabilities in your codebase.

Get Security Assessment