Standardseverity: MediumDraft
CAPEC-468Generic Cross-Browser Cross-Domain Theft
Abstraction
Standard
Status
Draft
Severity
Medium
Description
An attacker makes use of Cascading Style Sheets (CSS) injection to steal data cross domain from the victim's browser. The attack works by abusing the standards relating to loading of CSS: 1. Send cookies on any load of CSS (including cross-domain) 2. When parsing returned CSS ignore all data that does not make sense before a valid CSS descriptor is found by the CSS parser.
Related weaknesses· 4
Related attack patterns· 1
Exploits4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Inappropriate Encoding for Output Contextcwe-838 | 100% | live |
| Weakness | Improper Neutralizationcwe-707 | 100% | live |
| Weakness | Improper Neutralization of Quoting Syntaxcwe-149 | 100% | live |
| Weakness | Improper Handling of URL Encoding (Hex Encoding)cwe-177 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.