CWE-79
Overview
- CWE ID
- 79
- CWE Name
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Stable
Description
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.