VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 61 of 2,331
  • CVE-2023-30563HigJul 13, 2023
    risk 0.53cvss 8.2epss 0.00

    A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.

  • CVE-2023-35335HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-33171HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-28800HigJun 22, 2023
    risk 0.53cvss 8.1epss 0.01

    When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.

  • CVE-2023-33991HigJun 13, 2023
    risk 0.53cvss 8.2epss 0.00

    SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After…

  • CVE-2023-32686HigMay 27, 2023
    risk 0.53cvss 8.1epss 0.00

    Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files…

  • CVE-2023-0835HigApr 4, 2023
    risk 0.53cvss 8.2epss 0.01

    markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.

  • CVE-2023-27089HigApr 4, 2023
    risk 0.53cvss 8.2epss 0.00

    Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter.

  • CVE-2023-23467HigFeb 15, 2023
    risk 0.53cvss 8.1epss 0.00

    Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.

  • CVE-2023-21806HigFeb 14, 2023
    risk 0.53cvss 8.2epss 0.01

    Power BI Report Server Spoofing Vulnerability

  • CVE-2023-0776HigFeb 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions.…

  • CVE-2023-24508HigJan 26, 2023
    risk 0.53cvss 8.1epss 0.02

    Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The…

  • CVE-2023-22491HigJan 13, 2023
    risk 0.53cvss 8.1epss 0.01

    Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in…

  • CVE-2022-3033HigDec 22, 2022
    risk 0.53cvss 8.1epss 0.01

    If a Thunderbird user replied to a crafted HTML email containing a meta tag, with the meta tag having the http-equiv="refresh" attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL,…

  • CVE-2022-39017HigOct 31, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

  • CVE-2022-39016HigOct 31, 2022
    risk 0.53cvss 8.2epss 0.01

    Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.

  • CVE-2022-27494HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

  • CVE-2022-1059HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

  • CVE-2022-30571HigAug 2, 2022
    risk 0.53cvss 8.1epss 0.00

    The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected…

  • CVE-2022-22999HigJul 25, 2022
    risk 0.53cvss 8.2epss 0.00

    Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may…