CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (46,817)
page 277 of 2,341| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18775 | Med | 0.43 | 6.1 | 0.08 | Nov 1, 2018 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product. | ||
| CVE-2018-18548 | Med | 0.43 | 6.1 | 0.04 | Oct 24, 2018 | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. | ||
| CVE-2018-12650 | Med | 0.43 | 6.1 | 0.03 | Oct 24, 2018 | Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'. | ||
| CVE-2018-18437 | Med | 0.43 | 6.1 | 0.02 | Oct 23, 2018 | In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter. | ||
| CVE-2018-18324 | Med | 0.43 | 6.1 | 0.03 | Oct 15, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter. | ||
| CVE-2018-17784 | Med | 0.43 | 6.1 | 0.04 | Oct 10, 2018 | Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. | ||
| CVE-2018-17443 | Med | 0.43 | 6.1 | 0.06 | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS. | ||
| CVE-2018-17441 | Med | 0.43 | 6.1 | 0.06 | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS. | ||
| CVE-2018-17593 | Med | 0.43 | 6.1 | 0.02 | Oct 2, 2018 | AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||
| CVE-2018-17591 | Med | 0.43 | 6.1 | 0.02 | Oct 2, 2018 | AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||
| CVE-2018-17590 | Med | 0.43 | 6.1 | 0.02 | Oct 2, 2018 | AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||
| CVE-2018-17588 | Med | 0.43 | 6.1 | 0.02 | Oct 2, 2018 | AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||
| CVE-2018-17587 | Med | 0.43 | 6.1 | 0.02 | Oct 2, 2018 | AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||
| CVE-2018-17832 | Med | 0.43 | 6.1 | 0.02 | Oct 1, 2018 | XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | ||
| CVE-2018-17313 | Med | 0.43 | 6.1 | 0.02 | Sep 26, 2018 | On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi. | ||
| CVE-2018-17310 | Med | 0.43 | 6.1 | 0.02 | Sep 26, 2018 | On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi. | ||
| CVE-2018-7355 | Med | 0.43 | 6.1 | 0.02 | Sep 26, 2018 | All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS… | ||
| CVE-2018-12234 | Med | 0.43 | 6.1 | 0.03 | Sep 6, 2018 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter. | ||
| CVE-2018-16134 | Med | 0.43 | 6.1 | 0.04 | Aug 29, 2018 | Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. | ||
| CVE-2018-15740 | Med | 0.43 | 6.1 | 0.06 | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. |
- risk 0.43cvss 6.1epss 0.08
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.
- risk 0.43cvss 6.1epss 0.04
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
- risk 0.43cvss 6.1epss 0.03
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'.
- risk 0.43cvss 6.1epss 0.02
In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.
- risk 0.43cvss 6.1epss 0.03
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.
- risk 0.43cvss 6.1epss 0.04
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
- risk 0.43cvss 6.1epss 0.02
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- risk 0.43cvss 6.1epss 0.02
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- risk 0.43cvss 6.1epss 0.02
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- risk 0.43cvss 6.1epss 0.02
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- risk 0.43cvss 6.1epss 0.02
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- risk 0.43cvss 6.1epss 0.02
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
- risk 0.43cvss 6.1epss 0.02
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
- risk 0.43cvss 6.1epss 0.02
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
- risk 0.43cvss 6.1epss 0.02
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS…
- risk 0.43cvss 6.1epss 0.03
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.
- risk 0.43cvss 6.1epss 0.04
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
- risk 0.43cvss 6.1epss 0.06
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.