Weaknesses of type CWE-80

586 results

Falta de neutralização de tags HTML relacionadas a scripts (XSS básico)

O aplicativo web recebe entrada do usuário e a exibe na página sem sanitizar tags HTML/JavaScript, permitindo que um atacante injete scripts maliciosos que executam no navegador da vítima. O risco é roubo de sessões, credenciais, redirecionamento para sites maliciosos ou modificação do conteúdo exibido.

Example

Um campo de busca que mostra 'Você pesquisou por: <script>alert(document.cookie)</script>' sem escapar a entrada. O script executa no navegador de quem clica no link compartilhado, vazando cookies de sessão.

How to mitigate

Sempre escapar (encode) caracteres especiais HTML (< > " &) na saída ou usar bibliotecas de sanitização robustas (DOMPurify, Bleach). Implementar Content Security Policy (CSP) para bloquear scripts inline não-autorizado como camada adicional de defesa.

CVE-2020-11001MEDIUMPossible XSS attack in WagtailEPSS 1.3%CVE-2018-19952If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP SystEPSS 1.3%CVE-2022-39348MEDIUMTwisted vulnerable to NameVirtualHost Host header injectionEPSS 1.2%CVE-2022-0989NS WooCommerce Watermark <= 2.11.3 - Abuse of FunctionalityEPSS 1.2%CVE-2023-39216CRITICALImproper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privEPSS 1.2%CVE-2020-5283LOWXSS vulnerability in CVS show_subdir_lastmod supportEPSS 1.2%CVE-2024-41810MEDIUMHTML injection in HTTP redirect bodyEPSS 1.2%CVE-2019-13923A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the afEPSS 1.1%CVE-2022-28703CRITICALA stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.EPSS 1.1%CVE-2022-24749MEDIUMBasic Cross-site Scripting and Unrestricted Upload of File with Dangerous Type in SyliusEPSS 1.1%CVE-2017-16015Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the applicatiEPSS 1.1%CVE-2024-11954MEDIUMPimcore Search Document cross site scriptingEPSS 1.1%CVE-2019-6577A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor PaneEPSS 1.1%CVE-2021-43862LOWSelf XSS on user inputEPSS 1.0%CVE-2021-29503HIGHImproper Neutralization of Script-Related HTML Tags in NotesEPSS 1.0%CVE-2020-2495Cross-site scripting vulnerability in QTS and QuTS heroEPSS 1.0%CVE-2020-2496Cross-site scripting vulnerability in QTS and QuTS heroEPSS 1.0%CVE-2020-27126MEDIUMCisco Webex Meetings API Cross-Site Scripting VulnerabilityEPSS 1.0%CVE-2017-16043Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will rEPSS 1.0%CVE-2019-10933A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate UserEPSS 1.0%