Falhas do tipo CWE-79

28.626 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2018-0450—Cisco Data Center Network Manager Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43170MEDIUMA stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of RukEPSS 0.9%CVE-2018-15400—Cisco Cloud Services Platform 2100 Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43166MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1EPSS 0.9%CVE-2018-15434—Cisco Unified IP Phone 7900 Series Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2026-22813CRITICALMalicious website can execute commands on the local system through XSS in the OpenCode web UIEPSS 0.9%CVE-2022-43169MEDIUMA stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of RukovoEPSS 0.9%CVE-2022-43165MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1EPSS 0.9%CVE-2022-43164MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 aEPSS 0.9%CVE-2018-0452—Cisco Tetration Analytics Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2019-1655MEDIUMCisco Webex Meetings Server Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2018-19954—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2019-9509MEDIUMThe web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected cross site scriptingEPSS 0.9%CVE-2018-19956—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2021-24976—Smart SEO Tool < 3.0.6 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2018-19955—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2023-2587HIGH Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the weEPSS 0.9%CVE-2018-16468—In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.EPSS 0.9%CVE-2023-39513MEDIUMStored Cross-site Scripting on host.php verbose data-query debug view in CactiEPSS 0.9%CVE-2021-23038—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stoEPSS 0.9%