Falhas do tipo CWE-79

28.677 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2024-29931HIGHWordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.8%CVE-2024-26092MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.8%CVE-2021-25103—GTranslate < 2.9.7 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-1457CRITICALStore XSS in title parameter executing at EditUser Page & EditProducto page in neorazorx/facturascriptsEPSS 0.8%CVE-2021-25102—All In One WP Security < 4.4.11 - Authenticated Reflected Cross-Site ScriptingEPSS 0.8%CVE-2024-25090MEDIUMApache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users modeEPSS 0.8%CVE-2019-15602—The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability inEPSS 0.8%CVE-2022-40044MEDIUMCentreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at ConfEPSS 0.8%CVE-2022-0942CRITICALStored XSS due to Unrestricted File Upload in star7th/showdocEPSS 0.8%CVE-2019-15603—The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directoryEPSS 0.8%CVE-2024-40508HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConferenceEPSS 0.8%CVE-2023-6650MEDIUMSourceCodester Simple Invoice Generator System login.php cross site scriptingEPSS 0.8%CVE-2021-22723—A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerEPSS 0.8%CVE-2024-40507HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.EPSS 0.8%CVE-2021-20654—Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named EPSS 0.8%CVE-2023-6649MEDIUMPHPGurukul Teacher Subject Allocation Management System index.php cross site scriptingEPSS 0.8%CVE-2023-6297MEDIUMPHPGurukul Nipah Virus Testing Management System Search Report Page patient-search-report.php cross site scriptingEPSS 0.8%CVE-2023-6465MEDIUMPHPGurukul Nipah Virus Testing Management System registered-user-testing.php cross site scriptingEPSS 0.8%CVE-2022-2865HIGHA cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3EPSS 0.8%CVE-2021-44163MEDIUMChain Sea Information Integration Co., Ltd ai chatbot system - Reflected XSSEPSS 0.8%