Detailedlikelihood: Highseverity: Very HighStable

CAPEC-592Stored XSS

Abstraction
Detailed
Status
Stable
Likelihood
High
Severity
Very High

Description

An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently "stored" within the data storage of a vulnerable web application as valid input. Metadata: detailed CAPEC pattern, status stable, likelihood high, severity very high. Underlying weakness: CWE-79. Related CAPEC pattern: [object Object].

Related weaknesses· 1

CWE-79

Related attack patterns· 1

CAPEC-63 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')cwe-79100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Reflected XSS
CAPEC
XSS Through HTTP Query Strings
CAPEC
Cross-Site Scripting (XSS)
CAPEC
DOM-Based XSS
CAPEC
XSS Targeting Error Pages
CAPEC
XSS Through HTTP Headers
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.