VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 39 of 2,331
  • CVE-2022-41555HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.

  • CVE-2022-40965HigOct 27, 2022
    risk 0.57cvss 8.7epss 0.11

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

  • CVE-2022-36098HigSep 8, 2022
    risk 0.57cvss 8.9epss 0.71

    XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor,…

  • CVE-2022-30576HigAug 16, 2022
    risk 0.57cvss 8.7epss 0.01

    The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute…

  • CVE-2022-1948HigJul 28, 2022
    risk 0.57cvss 8.7epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

  • CVE-2022-32114HigJul 13, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…

  • CVE-2022-2235HigJul 1, 2022
    risk 0.57cvss 8.7epss 0.01

    Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

  • CVE-2022-2230HigJul 1, 2022
    risk 0.57cvss 8.1epss 0.56

    A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

  • CVE-2022-2140HigJun 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.

  • CVE-2021-26636HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.

  • CVE-2022-21937HigJun 15, 2022
    risk 0.57cvss 8.7epss 0.01

    Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.

  • CVE-2022-27183HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterprise, not for download on SplunkBase, and not installed on…

  • CVE-2022-24855HigApr 14, 2022
    risk 0.57cvss 8.7epss 0.01

    Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links…

  • CVE-2022-22182HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects: Juniper…

  • CVE-2022-1190HigApr 4, 2022
    risk 0.57cvss 8.7epss 0.87

    Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

  • CVE-2022-24386HigMar 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

  • CVE-2022-24709HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.01

    @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for…

  • CVE-2022-23013HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an…

  • CVE-2022-21690HigJan 18, 2022
    risk 0.57cvss 8.7epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is…

  • CVE-2021-39946HigJan 18, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis