CWE-97

Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

High

Description

The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.

Potential Impact

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-97 vulnerabilities in your codebase.

Get Security Assessment