CWE-692: Incomplete Denylist to Cross-Site Scripting

CompoundDraft

The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.

View on MITRE
Back to CWE Lookup

Extended Description

While XSS might seem simple to prevent, web browsers vary so widely in how they parse web pages, that a denylist cannot keep track of all the variations. The "XSS Cheat Sheet" [REF-714] contains a large number of attacks that are intended to bypass incomplete denylists.

Technical Details

Structure
Chain

Applicable To

Languages
Not Language-Specific
Platforms

Learn More