Weaknesses of type CWE-79

28,832 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-43694MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the image manipulation library EPSS 0.6%CVE-2024-3532LOWCampcodes Complete Online Student Management System attendance_view.php cross site scriptingEPSS 0.6%CVE-2020-6159—URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacksEPSS 0.6%CVE-2019-6142—It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply thEPSS 0.6%CVE-2024-3529LOWCampcodes Complete Online Student Management System students_view.php cross site scriptingEPSS 0.6%CVE-2022-43692MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS - user can cause an administrator EPSS 0.6%CVE-2019-6853—A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 99EPSS 0.6%CVE-2022-43968MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sEPSS 0.6%CVE-2024-43715MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2022-27546HIGHHCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2024-43719MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-43713MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-43721MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-43722MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-43712MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-3533LOWCampcodes Complete Online Student Management System academic_year_view.php cross site scriptingEPSS 0.6%CVE-2022-43967MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to EPSS 0.6%CVE-2024-43723MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2022-0447—Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_typesEPSS 0.6%CVE-2023-0087MEDIUMSwifty Page Manager <= 3.0.1 - Authenticated (Administrator+) Stored Cross-Site ScriptingEPSS 0.6%