Falhas do tipo CWE-79

28.634 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2020-36635LOWOpenMRS Appointment Scheduling Module AppointmentTypeValidator.java validateFieldName cross site scriptingEPSS 0.9%CVE-2019-13943—A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versiEPSS 0.9%CVE-2021-25062—Orders Tracking for WooCommerce < 1.1.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2024-23645MEDIUMGLPI reflected XSS in reports pagesEPSS 0.9%CVE-2016-5819—Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflecEPSS 0.9%CVE-2015-9102—Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote autheEPSS 0.9%CVE-2022-2826LOWAn issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.1EPSS 0.9%CVE-2020-26225HIGHReflected XSS in PrestaShop Product CommentsEPSS 0.9%CVE-2021-21319MEDIUMSeveral stored XSSEPSS 0.9%CVE-2022-42989CRITICALERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.EPSS 0.9%CVE-2018-3780—A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-intEPSS 0.9%CVE-2018-0276—A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agaEPSS 0.9%CVE-2024-57514MEDIUMThe TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web EPSS 0.9%CVE-2019-1733MEDIUMCisco NX-OS Software NX-API Sandbox Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-40956MEDIUMWhen injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. EPSS 0.9%CVE-2024-30875HIGHCross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and exeEPSS 0.9%CVE-2021-34653MEDIUMWP Fountain <= 1.5.9 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2015-10073LOWtinymighty WikiSEO Meta Property Tag WikiSEO.body.php modifyHTML cross site scriptingEPSS 0.9%CVE-2023-29712MEDIUMCross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to EPSS 0.9%CVE-2021-24720—GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%