Weaknesses of type CWE-79

28,406 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-24746Sassy Social Share < 3.3.40 - Reflected Cross-Site ScriptingEPSS 2.2%CVE-2023-6710MEDIUMMod_cluster/mod_proxy_cluster: stored cross site scriptingEPSS 2.2%CVE-2018-0242A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attEPSS 2.2%CVE-2023-42628CRITICALStored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83EPSS 2.2%CVE-2023-42629CRITICALStored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 EPSS 2.2%CVE-2024-4406HIGHXiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution VulnerabilityEPSS 2.2%CVE-2016-9490ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerabilityEPSS 2.2%CVE-2022-23988WS Form < 1.8.176 - Unauthenticated Stored Cross-Site ScriptingEPSS 2.2%CVE-2022-47870MEDIUMA Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to iEPSS 2.2%CVE-2020-1456MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 2.2%CVE-2018-8568MEDIUMAn elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.2%CVE-2022-0189WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)EPSS 2.2%CVE-2018-0118A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attackeEPSS 2.2%CVE-2019-3847MEDIUMA vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such aEPSS 2.2%CVE-2024-26152MEDIUMLabel Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config EPSS 2.2%CVE-2017-12248A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to cEPSS 2.2%CVE-2018-0223A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attEPSS 2.2%CVE-2018-0219A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remotEPSS 2.2%CVE-2018-0144A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attaEPSS 2.2%CVE-2018-0212A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 2.2%