Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE CAPEC-243: XSS Targeting HTML Attributes (Detailed Attack Pattern - Medium Severity)

MITRE CAPEC-243 (XSS Targeting HTML Attributes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An…

What MITRE CAPEC-243: XSS Targeting HTML Attributes (Detailed Attack Pattern - Medium Severity) requires

MITRE CAPEC-243 (XSS Targeting HTML Attributes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts commands to perform cross-site scripting (XSS) actions in HTML attributes. Many filters do not adequately sanitize attributes against the presence of potentially dangerous commands even if they adequately sanitize tags. For example, dangerous expressions could be inserted into a style attribute in an anchor tag, resulting in the execution of malicious code when the resulting page is rendered. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-83.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://capec.mitre.org/data/definitions/243.html

SHA-256 integrity: c979b2332f795cb4668439f13f3150e380ef5c1a5125e3058c2e8b9d7aa56246

Primary Citations — 7 traced to source

  • MITRE CAPEC-243: XSS Targeting HTML Attributes (https://capec.mitre.org/data/definitions/243.html)
  • CWE-83: underlying weakness (http://cwe.mitre.org/data/definitions/83.html)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.