COMMON WEAKNESS ENUMERATIONIncomplete
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
Abstraction
Base
Structure
Simple
Likelihood of Exploit
Medium
Understand the problem
What is the problem?
Extended description
Terminology
Alternate terms and usages
Mass Assignment
AutoBinding
PHP Object Injection
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Lifecycle phase
Implementation
Risk
What does successful exploitation lead to?
Modify Application Data
Execute Unauthorized Code or Commands
Varies by ContextAlter Execution Logic
Defence
How is it prevented and fixed?
Implementation
Implementation-phase defence
Detail
Implementation
Implementation-phase defence
Architecture and Design · Implementation
Defence to apply across several lifecycle phases
Detail
Architecture and Design · Implementation
Defence to apply across several lifecycle phases
Implementation
Input Validation
Detail
Implementation
Input Validation
Implementation · Architecture and Design
Refactoring
Detail
Implementation · Architecture and Design
Refactoring
Verification