Weaknesses of type CWE-79

28,639 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2018-18991—Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted UEPSS 0.9%CVE-2022-23058—ERPNext - Stored XSS in My SettingsEPSS 0.9%CVE-2018-17904—Reliance 4 SCADA/HMI, Version 4.7.3 Update 3 and prior. This vulnerability could allow an unauthorized attacker to inject arbitrary code.EPSS 0.9%CVE-2022-23072—Recipes - Stored XSS in Add to CartEPSS 0.9%CVE-2022-23056—ERPNext - Stored XSS leads to account takoverEPSS 0.9%CVE-2023-36030MEDIUMMicrosoft Dynamics 365 Sales Spoofing VulnerabilityEPSS 0.9%CVE-2022-23074—Recipes - Stored XSS in Name ParameterEPSS 0.9%CVE-2019-13538—3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library conEPSS 0.9%CVE-2023-0514MEDIUMMembership Database <= 1.0 - Reflected XSSEPSS 0.9%CVE-2022-0527MEDIUMCross-site Scripting (XSS) - Stored in chatwoot/chatwootEPSS 0.9%CVE-2021-4050MEDIUMCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.9%CVE-2023-0948MEDIUMJapanized For WooCommerce < 2.5.8 - Reflected XSSEPSS 0.9%CVE-2017-12346—Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into EPSS 0.9%CVE-2017-12347—Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into EPSS 0.9%CVE-2022-43499MEDIUMStored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administratiEPSS 0.9%CVE-2023-1546MEDIUMMyCryptoCheckout < 2.124 - Reflected XSSEPSS 0.9%CVE-2022-32159—Openlibrary - Stored XSSEPSS 0.9%CVE-2022-1527—WP 2FA < 2.2.1 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-1604—MailerLite < 1.5.4 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-1474—WP Event Manager < 3.1.28 - Reflected Cross-Site ScriptingEPSS 0.8%