What MITRE CAPEC-137: Parameter Injection (Meta Attack Pattern - Medium Severity) requires
MITRE CAPEC-137 (Parameter Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the content of request parameters for the purpose of undermining the security of the target. Some parameter encodings use text characters as separators. For example, parameters in a HTTP GET message are encoded as name-value pairs separated by an ampersand (&). Likelihood of attack: Medium. Typical severity: Medium. Parent pattern for CAPEC-134 Email Injection; CAPEC-135 Format String Injection; CAPEC-138 Reflection Injection; and others. Maps to weaknesses CWE-88.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/137.html
SHA-256 integrity: 1d1fb81e215e1126bdb8e39479690f7c9872a95131044845f30e25d8f2b2a513
Primary Citations — 7 traced to source
- MITRE CAPEC-137: Parameter Injection (https://capec.mitre.org/data/definitions/137.html)
- CWE-88: underlying weakness (http://cwe.mitre.org/data/definitions/88.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.