VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 85 of 2,331
  • CVE-2024-22130HigFeb 13, 2024
    risk 0.49cvss 7.6epss 0.00

    Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEBCUIF 701, WEBCUIF 730, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode…

  • CVE-2024-21637HigJan 11, 2024
    risk 0.49cvss 7.6epss 0.01

    Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege…

  • CVE-2023-41815HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774.

  • CVE-2023-6367HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Roles.   If a WhatsUp Gold user interacts with the crafted payload, the…

  • CVE-2023-6366HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Alert Center.   If a WhatsUp Gold user interacts with the crafted…

  • CVE-2023-6365HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within a device group.   If a WhatsUp Gold user interacts with the crafted…

  • CVE-2023-6364HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.  It is possible for an attacker to craft a XSS payload and store that value within a dashboard component.   If a WhatsUp Gold user interacts with the…

  • CVE-2023-36020HigDec 12, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-42478HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.

  • CVE-2023-6333HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.00

    The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session.

  • CVE-2023-41789HigNov 23, 2023
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allows an attacker to perform cookie hijacking and log in as that user without the need for credentials.…

  • CVE-2023-36007HigNov 14, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability

  • CVE-2023-36410HigNov 14, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-36031HigNov 14, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-26577HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the browsing session of the logged in user.

  • CVE-2023-1356HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Reflected cross-site scripting in the StudentSearch component in IDAttend’s IDWeb application 3.1.052 and earlier allows hijacking of a user’s browsing session by attackers who have convinced the said user to click on a malicious link.

  • CVE-2023-41843HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.00

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2023-41681HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.00

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2023-41680HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.00

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2023-32721HigOct 12, 2023
    risk 0.49cvss 7.6epss 0.01

    A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.