CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

What is CWE-75?

The product does not adequately filter user-controlled input for special elements with control implications.

Analyzing data...

Data statistics

RELATED CVES (365 DAYS)2
ABSTRACTIONClass

Vulnerabilities mapped to CWE-75

2 vulnerabilities100% increase year over year

Vulnerabilities in CISA KEV for CWE-75

0 vulnerabilities

Official definition

ByMitre CWE

The product does not adequately filter user-controlled input for special elements with control implications.

Characteristics

Modes of introduction

  • Implementation: REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Common consequences

ImpactScopeExplanation
Modify Application Data, Execute Unauthorized Code or CommandsIntegrity, Confidentiality, Availability—

Risk mitigations

  1. RequirementsProgramming languages and supporting technologies might be chosen which are not subject to these issues.
  2. ImplementationUtilize an appropriate mix of allowlist and denylist parsing to filter special element syntax from all input.
Sources (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan