VYPR

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

VariantIncompleteLikelihood: High

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-18 · CAPEC-193 · CAPEC-32 · CAPEC-86

CVEs mapped to this weakness (602)

page 15 of 31
  • CVE-2024-28831MedJun 25, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.

  • CVE-2023-47513MedJun 4, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.

  • CVE-2023-45635MedJun 4, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.

  • CVE-2023-40557MedJun 4, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accordion allows Code Injection.This issue affects Tabs & Accordion: from n/a through 1.3.10.

  • CVE-2023-39161MedJun 4, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.

  • CVE-2024-34699MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.01

    GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.

  • CVE-2024-25873MedFeb 22, 2024
    risk 0.35cvss 5.4epss 0.00

    Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2024-24812MedFeb 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0, portal pages are susceptible to Cross-Site Scripting (XSS) which can be used to inject malicious…

  • CVE-2024-24574MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in…

  • CVE-2023-39217MedAug 8, 2023
    risk 0.35cvss 5.3epss 0.02

    Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

  • CVE-2023-23548MedAug 1, 2023
    risk 0.35cvss 5.4epss 0.00

    Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.

  • CVE-2023-25833MedMay 10, 2023
    risk 0.35cvss 5.4epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data…

  • CVE-2023-26047MedMar 3, 2023
    risk 0.35cvss 6.5epss 0.01

    teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with special characters such as CR/LF and…

  • CVE-2023-26046MedMar 2, 2023
    risk 0.35cvss 6.5epss 0.01

    teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version 0.1.1 is vulnerable to bypassing common web attack rules when a specific HTML entities payload is used. This vulnerability allows an…

  • CVE-2023-22464MedJan 4, 2023
    risk 0.35cvss 5.4epss 0.01

    ViewVC is a browser interface for CVS and Subversion version control repositories. Versions prior to 1.2.3 and 1.1.30 are vulnerable to cross-site scripting. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a Subversion…

  • CVE-2022-28703MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger…

  • CVE-2022-39240MedSep 24, 2022
    risk 0.35cvss 5.4epss 0.01

    MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround.

  • CVE-2022-35509MedAug 10, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive…

  • CVE-2021-28803MedJul 1, 2021
    risk 0.35cvss 5.4epss 0.00

    This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.

  • CVE-2019-19285MedDec 14, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lead to XSS attacks if unsuspecting users are tricked into accessing a malicious link.