What MITRE CAPEC-209: XSS Using MIME Type Mismatch (Detailed Attack Pattern - Medium Severity) requires
MITRE CAPEC-209 (XSS Using MIME Type Mismatch) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a file with scripting content but where the specified MIME type of the file is such that scripting is not expected. The adversary tricks the victim into accessing a URL that responds with the script file. Some browsers will detect that the specified MIME type of the file does not match the actual type of its content and will automatically switch to using an interpreter for the real content type. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-79, CWE-20, CWE-646.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/209.html
SHA-256 integrity: dd28ed7bd5be728fbd7b320eb2586d6a64fca629a2fe5ceab13f04be9c462d15
Primary Citations — 10 traced to source
- MITRE CAPEC-209: XSS Using MIME Type Mismatch (https://capec.mitre.org/data/definitions/209.html)
- CWE-79: underlying weakness (http://cwe.mitre.org/data/definitions/79.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.