VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,610)

page 252 of 2,331
  • CVE-2023-51734MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Remote endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially…

  • CVE-2023-51733MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Local endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially…

  • CVE-2023-51732MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the IPsec Tunnel Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51731MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Hostname parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter…

  • CVE-2023-51730MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51729MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51728MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51727MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51726MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Server Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51725MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Contact Email Address parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to…

  • CVE-2023-51724MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at…

  • CVE-2023-51723MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Description parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51722MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51721MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 2 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51720MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 1 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51719MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Traceroute parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-3726MedJan 4, 2024
    risk 0.45cvss 6.9epss 0.01

    OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

  • CVE-2022-35950MedOct 9, 2023
    risk 0.45cvss 6.9epss 0.00

    OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through 4.2.10, 5.0.0 prior to 5.0.11, and 5.1.0 prior to 5.1.1, the JS payload added to the product name may be executed at the storefront when adding a note to the…

  • CVE-2023-30564MedJul 13, 2023
    risk 0.45cvss 6.9epss 0.00

    Alaris Systems Manager does not perform input validation during the Device Import Function.

  • CVE-2023-27474HigMar 6, 2023
    risk 0.45cvss 8.0epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL. An attacker could exploit this to email users urls to…