CVEbaza.plSłownik CWECWE-692
Common Weakness Enumeration

CWE-692

Incomplete Denylist to Cross-Site Scripting

Kategoria: CompoundCVE: 10
Opis

Produkt wykorzystuje mechanizm ochrony oparty na liście zakazów do obrony przed atakami XSS, jednak lista ta jest niekompletna. Pozwala to na wykonanie wariantów ataków XSS pomimo zastosowanej ochrony.

Description (EN)

The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.

Podatności CVE z CWE-692 (10)
6.5
CVSS
MEDIUM
CVE-2024-52305

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

pub. 2024-11-13
6.5
CVSS
MEDIUM
CVE-2023-26047

teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. This vulnerability allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application. An attacker can exploit this vulnerability to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks. The attacker can execute arbitrary JavaScript code on the victim's browser and steal sensitive information, such as login credentials and session tokens, or take control of the victim's browser and perform malicious actions. This issue has been patched in version 0.2.0.

pub. 2023-03-03
6.1
CVSS
MEDIUM
CVE-2026-71478

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.

pub. 2026-08-06
6.1
CVSS
MEDIUM
CVE-2025-20240

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

pub. 2025-09-24
5.3
CVSS
MEDIUM
CVE-2024-42214

HCL Aftermarket EPC jest podatny na ataki, ponieważ metoda HTTP OPTIONS jest włączona na serwerze. Metoda OPTIONS udostępnia listę metod obsługiwanych przez serwer, co pozwala atakującemu zawęzić i wzmocnić swoje działania.

pub. 2026-07-17
4.6
CVSS
MEDIUM
CVE-2024-30924

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

pub. 2024-04-18
4.4
CVSS
MEDIUM
CVE-2026-15295

Plugin Infinite Scroll – Ajax Load More dla WordPress jest podatny na Stored XSS poprzez ustawienia administratora we wszystkich wersjach do wersji 7.0.1 włącznie z powodu niedostatecznej sanityzacji danych wejściowych i braku escapingu wyjścia. Umożliwia to uwierzytelnionym atakującym z uprawnieniami administratora i wyższymi wstrzyknięcie arbitralnego kodu JavaScript na stronach, które będą wykonywane gdy użytkownik uzyska dostęp do zainfekowanej strony. Problem dotyczy wyłącznie instalacji multi-site oraz instalacji, w których unfiltered_html została wyłączona.

pub. 2026-07-10
4.3
CVSS
MEDIUM
CVE-2024-23569

HCL Aftermarket EPC jest podatny na ataki, ponieważ serwer nie jest skonfigurowany z nagłówkiem "X-XSS-Protection".

pub. 2026-07-17
2.9
CVSS
LOW
CVE-2025-49590

CryptPad to pakiet narzędzi do współpracy. Przed wersją 2025.3.0 funkcjonalność "Link Bouncer" próbuje filtrować javascript URIs, aby zapobiec Cross-Site Scripting (XSS), jednak można to obejść. Istnieje ścieżka kodu "early allow", która uruchamia się przed sprawdzeniem protokołu/schematu URI, którą może wykorzystać złośliwie skonstruowany URI. Problem został naprawiony w wersji 2025.3.0.

pub. 2025-06-18
1.3
CVSS
LOW
CVE-2025-53904

Kanał Scratch to portal informacyjny, który znajduje się w fazie rozwojowej. Plik `/api/admin.js` zawiera kod, który może uczynić stronę internetową podatną na XSS. W momencie publikacji nie istniały znane łatki.

pub. 2025-07-16
Informacje
ID: CWE-692
Typ: Compound
Podatności: 10
MITRE CWE ↗
← Słownik CWE