angler-fishThe Vulnerability History Project

CWE-692: Incomplete Denylist to Cross-Site Scripting

"The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed." - Entry from the Common Weakness Enumeration For more info visit <a href="https://cwe.mitre.org/data/definitions/692.html" target="_blank" rel="noopener noreferrer">CWE-692</a>

Examples


    There are no articles here... yet

expand_less