- Home
- All questions
- Question 464
CISSP study material · question 464 of 500
Which description matches OWASP's 2025 definition of an injection vulnerability?
Show the answer
Answer: D. Untrusted input reaches an interpreter and part of it is executed as a command rather than treated as data.
The flaw lets untrusted input reach an interpreter, which then treats part of what arrived as instructions rather than as ordinary data.
Source: OWASP Top 10 A05:2025 (OWASP) — OWASP Top 10:2025 A05 Injection > Description