VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2094 of 2,331
  • CVE-2020-1933MedJan 28, 2020
    risk 0.00cvss 6.1epss 0.03

    A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.

  • CVE-2019-19858MedJan 15, 2020
    risk 0.00cvss 4.8epss 0.01

    An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter.

  • CVE-2019-19856MedJan 15, 2020
    risk 0.00cvss 4.8epss 0.01

    An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.

  • CVE-2019-19855MedJan 15, 2020
    risk 0.00cvss 4.8epss 0.01

    An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.

  • CVE-2020-6847MedJan 11, 2020
    risk 0.00cvss 5.4epss 0.01

    OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that contains JavaScript.

  • CVE-2019-20374CriJan 9, 2020
    risk 0.00cvss 9.6epss 0.02

    A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to…

  • CVE-2020-6632MedJan 9, 2020
    risk 0.00cvss 6.1epss 0.01

    In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.

  • CVE-2019-20365MedJan 8, 2020
    risk 0.00cvss 6.1epss 0.01

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.

  • CVE-2019-20364MedJan 8, 2020
    risk 0.00cvss 6.1epss 0.01

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.

  • CVE-2019-20363MedJan 8, 2020
    risk 0.00cvss 6.1epss 0.01

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.

  • CVE-2020-5497MedJan 4, 2020
    risk 0.00cvss 6.1epss 0.02

    The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.

  • CVE-2019-20042MedDec 27, 2019
    risk 0.00cvss 6.1epss 0.03

    In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions…

  • CVE-2019-19388MedNov 29, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.

  • CVE-2019-19387MedNov 29, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.

  • CVE-2019-19386MedNov 29, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.

  • CVE-2019-19385MedNov 29, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.

  • CVE-2019-19384MedNov 29, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.

  • CVE-2019-19367MedNov 27, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • CVE-2019-19366MedNov 27, 2019
    risk 0.00cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.

  • CVE-2019-19040MedNov 17, 2019
    risk 0.00cvss 6.1epss 0.01

    KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"' substring.