VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 2096 of 2,331
  • CVE-2019-14967MedAug 12, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

  • CVE-2018-20858MedAug 9, 2019
    risk 0.00cvss 6.1epss 0.01

    Recommender before 2018-07-18 allows XSS.

  • CVE-2019-14672MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page.

  • CVE-2019-14670MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.

  • CVE-2019-14669MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.

  • CVE-2019-14668MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link.

  • CVE-2019-14667MedAug 5, 2019
    risk 0.00cvss 6.1epss 0.01

    Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.

  • CVE-2019-14550MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit…

  • CVE-2019-14549MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the…

  • CVE-2019-14548MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious…

  • CVE-2019-14547MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker…

  • CVE-2019-14546MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his…

  • CVE-2018-20859MedJul 30, 2019
    risk 0.00cvss 6.1epss 0.01

    edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.

  • CVE-2019-14331MedJul 28, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

  • CVE-2019-14330MedJul 28, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

  • CVE-2019-14329MedJul 28, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.

  • CVE-2018-18676MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter.

  • CVE-2018-18675MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter.

  • CVE-2018-18672MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter.

  • CVE-2018-18670MedJul 23, 2019
    risk 0.00cvss 6.1epss 0.02

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter.