Crlf-injection-logs
Crlf injection logs
crlf-injection-logs
crlf-injection-logs
When data from an untrusted source is put into a logger and not neutralized correctly, an attacker could forge log entries or include malicious content.
Likelihood: MEDIUM
Confidence: MEDIUM
CWE:
- CWE-93: Improper Neutralization of CRLF Sequences (‘CRLF Injection’)
OWASP:
- A03:2021 - Injection