The product does not properly restrict reading from or writing to dynamically-identified variables.
For any externally-influenced input, check the input against an allowlist of internal program variables that are allowed to be modified.
Refactor the code so that internal program variables do not need to be dynamically identified.
Our security experts can help you identify and remediate CWE-914 vulnerabilities in your codebase.
Get Security Assessment