VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 265 of 2,341
  • CVE-2020-12779MedAug 10, 2020
    risk 0.44cvss 6.8epss 0.01

    Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

  • CVE-2020-7017MedJul 27, 2020
    risk 0.44cvss 6.7epss 0.01

    In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the…

  • CVE-2013-2679MedFeb 18, 2020
    risk 0.44cvss 6.1epss 0.20

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to…

  • CVE-2020-8512MedFeb 1, 2020
    risk 0.44cvss 6.1epss 0.15

    In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.

  • CVE-2019-19368MedDec 16, 2019
    risk 0.44cvss 6.1epss 0.26

    A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts

  • CVE-2019-17120MedOct 17, 2019
    risk 0.44cvss 6.1epss 0.50

    A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting…

  • CVE-2019-15889MedSep 3, 2019
    risk 0.44cvss 6.1epss 0.11

    The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

  • CVE-2019-3964MedAug 20, 2019
    risk 0.44cvss 6.1epss 0.53

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

  • CVE-2019-3963MedAug 20, 2019
    risk 0.44cvss 6.1epss 0.53

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

  • CVE-2019-15053MedAug 14, 2019
    risk 0.44cvss 6.8epss 0.01

    The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.

  • CVE-2019-14750MedAug 7, 2019
    risk 0.44cvss 6.1epss 0.11

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields…

  • CVE-2019-14696MedAug 6, 2019
    risk 0.44cvss 6.1epss 0.16

    Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

  • CVE-2019-5450MedJul 30, 2019
    risk 0.44cvss 6.8epss 0.01

    Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.

  • CVE-2019-0308MedJun 12, 2019
    risk 0.44cvss 6.8epss 0.01

    An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to…

  • CVE-2019-8937MedMay 17, 2019
    risk 0.44cvss 6.1epss 0.11

    HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.

  • CVE-2019-8929MedMay 17, 2019
    risk 0.44cvss 6.1epss 0.11

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.

  • CVE-2019-0186MedApr 26, 2019
    risk 0.44cvss 6.1epss 0.21

    The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file

  • CVE-2019-9955MedApr 22, 2019
    risk 0.44cvss 6.1epss 0.21

    On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx'…

  • CVE-2018-15614MedJan 23, 2019
    risk 0.44cvss 6.8epss 0.01

    A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0…

  • CVE-2018-19877MedDec 5, 2018
    risk 0.44cvss 6.1epss 0.19

    login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.