Falhas do tipo CWE-79

28.628 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2021-23038—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stoEPSS 0.9%CVE-2020-8120—A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.EPSS 0.9%CVE-2021-39328MEDIUMSimple Job Board <= 2.9.4 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-39357MEDIUMLeaky Paywall <= 4.16.5 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2022-0719HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.9%CVE-2026-51133MEDIUMCross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary codEPSS 0.9%CVE-2015-20019—Content text slider on post < 6.9 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%CVE-2021-41086HIGHClipboard-based XSS in jsuitesEPSS 0.9%CVE-2022-44948MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?moEPSS 0.9%CVE-2022-27878MEDIUMOn all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions priEPSS 0.9%CVE-2018-18997—Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrativEPSS 0.9%CVE-2021-43861HIGHIncorrect sanitisation function leads to `XSS`EPSS 0.9%CVE-2017-20008—myCRED < 1.7.8 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2007-1679MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web EPSS 0.9%CVE-2018-0367—A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attackerEPSS 0.9%CVE-2022-26105—SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unautheEPSS 0.9%CVE-2020-27832—A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notificaEPSS 0.9%CVE-2018-15634HIGHCross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows reEPSS 0.9%CVE-2024-11587MEDIUMidcCMS classProvCity.php GetCityOptionJs cross site scriptingEPSS 0.9%CVE-2019-1719MEDIUMCisco Identity Services Engine Cross-Site Scripting VulnerabilityEPSS 0.9%