VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 246 of 2,331
  • CVE-2022-41706HigNov 25, 2022
    risk 0.46cvss 8.2epss 0.01

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

  • CVE-2022-43984HigNov 25, 2022
    risk 0.46cvss 8.2epss 0.01

    Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use…

  • CVE-2022-43983HigNov 25, 2022
    risk 0.46cvss 8.2epss 0.01

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.

  • CVE-2022-41905HigNov 11, 2022
    risk 0.46cvss 8.2epss 0.00

    WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set…

  • CVE-2022-39285HigOct 7, 2022
    risk 0.46cvss 7.6epss 0.04

    ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This then allows a malicious user to provide code that will execute…

  • CVE-2022-40313HigSep 30, 2022
    risk 0.46cvss 7.1epss 0.01

    Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

  • CVE-2022-2753MedSep 19, 2022
    risk 0.46cvss 6.1epss 0.83

    The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made

  • CVE-2022-37318HigAug 25, 2022
    risk 0.46cvss 7.0epss 0.01

    Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the…

  • CVE-2022-30690MedAug 22, 2022
    risk 0.46cvss 6.1epss 0.84

    A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP…

  • CVE-2022-28730MedAug 4, 2022
    risk 0.46cvss 6.1epss 0.85

    A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This vulnerability leverages CVE-2021-40369,…

  • CVE-2022-27166MedAug 4, 2022
    risk 0.46cvss 6.1epss 0.85

    A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

  • CVE-2022-29882HigMay 20, 2022
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not handle uploaded files correctly. An unauthenticated attacker could take advantage of this situation to store an XSS attack, which could - when a legitimate user accesses the error logs…

  • CVE-2022-29876HigMay 20, 2022
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform…

  • CVE-2021-32927HigApr 22, 2022
    risk 0.46cvss 7.1epss 0.01

    An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.

  • CVE-2022-24833HigApr 11, 2022
    risk 0.46cvss 8.2epss 0.01

    PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the…

  • CVE-2022-24722HigMar 2, 2022
    risk 0.46cvss 8.1epss 0.01

    VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulnerability that has the potential to impact anyone using translations with the view_component gem. Data received via user input and…

  • CVE-2022-21648HigJan 4, 2022
    risk 0.46cvss 8.2epss 0.01

    Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue…

  • CVE-2021-43818HigDec 13, 2021
    risk 0.46cvss 8.2epss 0.02

    lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a…

  • CVE-2021-41951MedNov 15, 2021
    risk 0.46cvss 6.1epss 0.78

    ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be…

  • CVE-2021-33618MedNov 10, 2021
    risk 0.46cvss 6.1epss 0.79

    Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.