Confused Deputy
Source: cwe.mitre.org
Published:
<p>If an attacker cannot directly a target, but the product has access to the target, then the attacker can send a request to the product and have it be forwarded to the target. The request would appear to be coming from the product's system, not the attacker's system. As a result, the attacker can