VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 19 of 2,331
  • CVE-2023-22585CriJun 11, 2023
    risk 0.59cvss 9.0epss 0.01

    The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.

  • CVE-2023-22582CriJun 11, 2023
    risk 0.59cvss 9.0epss 0.01

    The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting.

  • CVE-2023-0432CriMar 31, 2023
    risk 0.59cvss 9.0epss 0.01

    The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web…

  • CVE-2021-33351CriMar 8, 2023
    risk 0.59cvss 9.0epss 0.01

    Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.

  • CVE-2022-48311CriFeb 6, 2023
    risk 0.59cvss 9.0epss 0.01

    **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability…

  • CVE-2022-34322CriJan 1, 2023
    risk 0.59cvss 9.0epss 0.01

    Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Notify Users…

  • CVE-2022-31358CriDec 14, 2022
    risk 0.59cvss 9.0epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

  • CVE-2022-41563CriDec 13, 2022
    risk 0.59cvss 9.0epss 0.01

    The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for…

  • CVE-2022-37721CriNov 25, 2022
    risk 0.59cvss 9.0epss 0.01

    PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

  • CVE-2022-37720CriNov 25, 2022
    risk 0.59cvss 9.0epss 0.01

    Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the…

  • CVE-2022-42989CriNov 22, 2022
    risk 0.59cvss 9.0epss 0.01

    ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.

  • CVE-2022-41558CriNov 15, 2022
    risk 0.59cvss 9.0epss 0.01

    The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server,…

  • CVE-2022-40289CriOct 31, 2022
    risk 0.59cvss 9.0epss 0.01

    The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.

  • CVE-2022-40288CriOct 31, 2022
    risk 0.59cvss 9.0epss 0.01

    The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.

  • CVE-2022-40287CriOct 31, 2022
    risk 0.59cvss 9.0epss 0.01

    The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account.

  • CVE-2020-19586CriSep 14, 2022
    risk 0.59cvss 9.0epss 0.01

    Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.

  • CVE-2022-28712CriAug 22, 2022
    risk 0.59cvss 9.0epss 0.03

    A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP…

  • CVE-2021-43702CriJul 5, 2022
    risk 0.59cvss 9.0epss 0.01

    ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

  • CVE-2022-25784CriMay 4, 2022
    risk 0.59cvss 9.1epss 0.01

    Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

  • CVE-2021-43932CriApr 28, 2022
    risk 0.59cvss 9.0epss 0.01

    Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.