VYPR

CWE-81

Improper Neutralization of Script in an Error Message Web Page

VariantIncomplete

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters that could be interpreted as web-scripting elements when they are sent to an error page.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-198

CVEs mapped to this weakness (9)

  • CVE-2022-4361CriJul 7, 2023
    risk 0.58cvss 10.0epss 0.01

    Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the…

  • CVE-2022-4137HigSep 25, 2023
    risk 0.46cvss 8.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a…

  • CVE-2025-24344MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the context of another user's browser via a crafted HTTP request.

  • CVE-2026-41568MedJun 12, 2026
    risk 0.40cvss 6.1epss 0.00

    Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or…

  • CVE-2024-6892MedAug 8, 2024
    risk 0.40cvss 6.1epss 0.01

    Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

  • CVE-2024-47882MedOct 24, 2024
    risk 0.31cvss 5.9epss 0.00

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the page if an attacker can…

  • CVE-2025-0883LowMar 12, 2025
    risk 0.14cvss epss 0.00

    Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager.  The vulnerability could reveal sensitive information retained by the browser. This issue affects Service Manager: 9.70, 9.71, 9.72, 9.80.

  • CVE-2024-47064MedSep 30, 2024
    risk 0.00cvss 6.1epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the…

  • CVE-2019-25027MedApr 23, 2021
    risk 0.00cvss 6.1epss 0.01

    Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL