VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 41 of 2,331
  • CVE-2020-35944HigJan 1, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.

  • CVE-2020-12517HigDec 17, 2020
    risk 0.57cvss 8.8epss 0.01

    On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).

  • CVE-2020-17147HigDec 10, 2020
    risk 0.57cvss 8.7epss 0.01

    Dynamics CRM Webclient Cross-site Scripting Vulnerability

  • CVE-2020-16946HigOct 16, 2020
    risk 0.57cvss 8.7epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-16945HigOct 16, 2020
    risk 0.57cvss 8.7epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-16944HigOct 16, 2020
    risk 0.57cvss 8.7epss 0.02

    This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server. An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint…

  • CVE-2020-1673HigOct 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient Cross-Site Scripting (XSS) protection in Juniper Networks J-Web and web based (HTTP/HTTPS) services allows an unauthenticated attacker to hijack the target user's HTTP/HTTPS session and perform administrative actions on the Junos device as the targeted user. This…

  • CVE-2020-7741CriOct 6, 2020
    risk 0.57cvss 9.9epss 0.01

    This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).

  • CVE-2020-12817HigSep 24, 2020
    risk 0.57cvss 8.8epss 0.02

    An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.

  • CVE-2020-9414HigJun 30, 2020
    risk 0.57cvss 8.8epss 0.02

    The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contains a vulnerability that theoretically allows an authenticated user with specific permissions to obtain the session identifier…

  • CVE-2020-2017HigMay 13, 2020
    risk 0.57cvss 8.8epss 0.01

    A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to PAN-OS and Panorama Web Interfaces could execute arbitrary JavaScript code in…

  • CVE-2020-8774HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.01

    Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.

  • CVE-2020-8477HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

  • CVE-2020-8985HigMar 24, 2020
    risk 0.57cvss 8.8epss 0.01

    ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

  • CVE-2013-4225HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content"…

  • CVE-2019-19979HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.

  • CVE-2019-13741HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

  • CVE-2019-12095HigOct 24, 2019
    risk 0.57cvss 8.8epss 0.01

    Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

  • CVE-2019-17495CriOct 10, 2019
    risk 0.57cvss 9.8epss 0.06

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product…

  • CVE-2019-0047HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos administrator to first perform certain diagnostic actions…