Skip to main content

Threats Tagged 'cwe-840'

View all threats tagged with 'cwe-840'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-840

Threats Tagged 'cwe-840'

Click on any threat for detailed analysis and mitigation recommendations

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

Join the discussion

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.

Join the discussion

A vulnerability exists in macrozheng mall versions 1.0.0 through 1.0.3 in the Payment Status Endpoint (/order/paySuccess). The issue involves manipulation of the orderId argument, which can enforce unintended behavioral workflow remotely. The vendor has not provided a patch or explanation, and the GitHub issue was deleted without comment. The CVSS score is 5.4, indicating a low severity level with limited impact on confidentiality but some impact on integrity and availability.

Join the discussion

CVE-2026-75081 is a medium severity vulnerability in Webkul Bagisto up to version 2.4.4. It involves manipulation of parameters (rma_qty, resolution_type, rma_reason_id) in the /customer/account/rma/store endpoint, resulting in enforcement of behavioral workflow. The vulnerability can be exploited remotely without user interaction. The vendor has acknowledged the issue, stating some fixes have been applied and others are planned for future releases. No public patch is currently confirmed.

Join the discussion

A vulnerability exists in WonderTrader up to version 0.9.9 in the Pending Order Handler component, specifically in the _undone_qty function. The issue involves manipulation of the getUndoneQty argument, which can enforce unintended behavioral workflow. The vulnerability can be exploited remotely. Public exploit code is available. The vendor has not responded to disclosure requests. The CVSS score is 4.3, indicating a low severity impact.

Join the discussion

A vulnerability exists in WonderTrader up to version 0.9.9 affecting the TraderDD::queryTrades function. The issue involves manipulation of the argument FID_JYLB, which can enforce behavioral workflow changes. The attack can be performed remotely but requires high complexity and is difficult to exploit. The vendor has not responded to disclosure, and no patch or fix information is available. The vulnerability has a low CVSS score of 3.7 and no known exploits in the wild.

Join the discussion

Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Join the discussion

CVE-2026-41973 is a permission control vulnerability in Huawei HarmonyOS related to business logic errors (CWE-840). Successful exploitation may impact system availability. The vulnerability has a medium severity with a CVSS score of 5.9. It affects multiple versions of HarmonyOS including 4.0.0, 4.2.0, 4.3.0, and 4.3.1. No official patch or remediation guidance is currently available from the vendor.

Join the discussion

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

Join the discussion

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: cwe-840
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses