CWE-692 — Incomplete Denylist to Cross-Site Scripting
CWE-692: Incomplete Denylist to Cross-Site Scripting
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Compound |
| Status | Draft |
| Likelihood of exploit | — |
Description
The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.
While XSS might seem simple to prevent, web browsers vary so widely in how they parse web pages, that a denylist cannot keep track of all the variations. The "XSS Cheat Sheet" [REF-714] contains a large number of attacks that are intended to bypass incomplete denylists.
Common consequences
- Confidentiality, Integrity, Availability: Execute Unauthorized Code or Commands
Mitigations
(none listed)
References
- CWE page: https://cwe.mitre.org/data/definitions/692.html
- CWE list: https://cwe.mitre.org/data/index.html
See all 1,245 pages under Weakness classes (CWE) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.