VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 60 of 2,331
  • CVE-2024-23862HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grndisplay.php, in the grnno parameter. Exploitation of this…

  • CVE-2024-23861HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/unitofmeasurementcreate.php, in the unitofmeasurementid…

  • CVE-2024-23860HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/currencylist.php, in the description parameter. Exploitation…

  • CVE-2024-23859HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructurelinecreate.php, in the flatamount parameter.…

  • CVE-2024-23858HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancelinecreate.php, in the batchno parameter.…

  • CVE-2024-23857HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlinecreate.php, in the batchno parameter. Exploitation of…

  • CVE-2024-23856HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/itemlist.php, in the description parameter. Exploitation of…

  • CVE-2024-23855HigJan 25, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxcodemodify.php, in multiple parameters. Exploitation of…

  • CVE-2024-22199CriJan 11, 2024
    risk 0.53cvss 9.3epss 0.00

    This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the…

  • CVE-2023-40461HigDec 4, 2023
    risk 0.53cvss 8.1epss 0.00

    The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.

  • CVE-2023-4667HigNov 28, 2023
    risk 0.53cvss 8.1epss 0.00

    The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface.  The root cause of the…

  • CVE-2023-37423HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2023-37422HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2023-37421HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2023-27515HigAug 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-29887HigAug 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-37501HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.00

    A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user's session and perform other attacks.

  • CVE-2023-37500HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.00

    A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacker could hijack a user's session and perform other attacks.

  • CVE-2023-37499HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.00

    A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An attacker could hijack a user's session and perform other attacks.

  • CVE-2023-34360HigJul 31, 2023
    risk 0.53cvss 8.2epss 0.00

    A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with regular user privilege, the remote attacker can perform a…