User Controllable JavaScript Event (XSS)
- Risk:
Informational
- Type:
- Passive
- CWE:
- CWE-20
- Summary
This check looks at user-supplied input in query string parameters and POST data to identify where certain HTML attribute values might be controlled. This provides hot-spot detection for XSS (cross-site scripting) that will require further review by a security analyst to determine exploitability.
- Solution
Validate all input and sanitize output it before writing to any Javascript on* events.
- Other info
- User-controlled javascript event(s) was found. Exploitability will need to be manually determined. The page at the following URL: http://example.com/i.php?place=moon&name=Foo includes the following Javascript event which may be attacker-controllable: User-input was found in the following data of an [onerror] event: foo The user input was: foo
Toys “R” Us Canada warns customers' info leaked in data breach
HP pulls update that broke Microsoft Entra ID auth on some AI PCs
Meet the new Clippy: Microsoft unveils Copilot's "Mico" avatar
CISA warns of Lanscope Endpoint Manager flaw exploited in attacks
Microsoft disables File Explorer preview for downloads to block attacks
North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets
Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions
North Korean Lazarus hackers targeted European defense companies
Secure AI at Scale and Speed — Learn the Framework in this Free Webinar
ThreatsDay Bulletin: $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More
CVE-2022-48503 Apple Multiple Products Unspecified Vulnerability
CVE-2016-7836 SKYSEA Client View Improper Authentication Vulnerability
CVE-2021-43226 Microsoft Windows Privilege Escalation Vulnerability
CVE-2025-33073 Microsoft Windows SMB Client Improper Access Control Vulnerability
CVE-2025-61884 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-6264 Rapid7 Velociraptor Incorrect Default Permissions Vulnerability
CVE-2017-0144 Microsoft SMBv1 Remote Code Execution Vulnerability
CVE-2017-3881 Cisco IOS and IOS XE Remote Code Execution Vulnerability
Free online web security scanner