VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 38 of 2,331
  • CVE-2023-32071CriMay 9, 2023
    risk 0.57cvss 9.0epss 0.70

    XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an…

  • CVE-2023-1094HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter.

  • CVE-2023-1031HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter.

  • CVE-2023-31223HigApr 25, 2023
    risk 0.57cvss 8.7epss 0.01

    Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.

  • CVE-2023-25313CriApr 25, 2023
    risk 0.57cvss 9.8epss 0.01

    OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.

  • CVE-2022-43955HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform…

  • CVE-2022-41330HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1…

  • CVE-2022-41566HigFeb 22, 2023
    risk 0.57cvss 8.7epss 0.00

    The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons:…

  • CVE-2022-41565HigFeb 22, 2023
    risk 0.57cvss 8.7epss 0.00

    The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system.…

  • CVE-2022-41334HigFeb 16, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when…

  • CVE-2023-22932HigFeb 14, 2023
    risk 0.57cvss 8.7epss 0.00

    In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The vulnerability affects instances with Splunk Web enabled. It does not affect Splunk Enterprise versions below 9.0.

  • CVE-2023-22468HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry out cross-site scripting…

  • CVE-2022-43524HigJan 5, 2023
    risk 0.57cvss 8.7epss 0.01

    A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an…

  • CVE-2022-45020HigDec 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2022-42750HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.01

    CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

  • CVE-2022-38374HigNov 2, 2022
    risk 0.57cvss 8.8epss 0.02

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and event logviews.

  • CVE-2022-40190HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in users’ browsers and…

  • CVE-2022-41702HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.

  • CVE-2022-41701HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.

  • CVE-2022-41651HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.