VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 263 of 2,341
  • CVE-2023-47549MedNov 14, 2023
    risk 0.44cvss 6.8epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.

  • CVE-2023-46252MedNov 7, 2023
    risk 0.44cvss 6.8epss 0.00

    Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different class-like functions, which…

  • CVE-2023-42474MedOct 10, 2023
    risk 0.44cvss 6.8epss 0.00

    SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.

  • CVE-2023-0828MedOct 3, 2023
    risk 0.44cvss 6.7epss 0.00

    Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.

  • CVE-2023-30962MedSep 12, 2023
    risk 0.44cvss 6.8epss 0.00

    The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .

  • CVE-2023-36473MedJul 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack…

  • CVE-2023-26059MedApr 24, 2023
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a…

  • CVE-2023-26061MedApr 24, 2023
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inject XSS. Input validation was missing during creation of a scheduled task. For an external attacker, it is very difficult…

  • CVE-2022-29273MedFeb 22, 2023
    risk 0.44cvss 6.1epss 0.60

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

  • CVE-2023-22722MedJan 26, 2023
    risk 0.44cvss 6.8epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make…

  • CVE-2022-46369MedJan 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields.

  • CVE-2022-39187MedJan 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors.

  • CVE-2022-41336MedJan 3, 2023
    risk 0.44cvss 6.8epss 0.01

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated attacker to perform a stored cross site scripting (XSS)…

  • CVE-2022-3709MedDec 1, 2022
    risk 0.44cvss 6.8epss 0.01

    A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2022-38803MedNov 30, 2022
    risk 0.44cvss 6.8epss 0.01

    Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting data as a PDF

  • CVE-2022-39810MedSep 9, 2022
    risk 0.44cvss 6.1epss 0.57

    An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar…

  • CVE-2021-25267MedMay 5, 2022
    risk 0.44cvss 6.8epss 0.01

    Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.

  • CVE-2022-27878MedMay 5, 2022
    risk 0.44cvss 6.8epss 0.01

    On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows…

  • CVE-2021-35229MedApr 21, 2022
    risk 0.44cvss 6.8epss 0.03

    Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query

  • CVE-2021-46387MedMar 1, 2022
    risk 0.44cvss 6.1epss 0.21

    ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks…