CWE-82: Improper Sanitization of Script in Attributes of IMG Tags in a Web Page
Improper Sanitization of Script in Attributes of IMG Tags in a Web Page
Weakness ID: 82 (Weakness Variant)
Status: Incomplete
Description
Description Summary
The web application does not filter or incorrectly filters
scripting elements within attributes of HTML IMG tags, such as the src
attribute.
Extended Description
Attackers can embed XSS exploits into the values for IMG attributes (e.g.
SRC) that is streamed and then executed in a victim's browser. Note that
when the page is loaded into a user's browsers, the exploit will
automatically execute.