CWE-346: Origin Validation Error
CWE-807: Reliance on Untrusted Inputs in a Security Decision
