Compliance Node Overview
MITRE CAPEC-588 (DOM-Based XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the client-side HTML being parsed by a web browser. Content served by a vulnerable web application includes script code used to manipulate the Document Object Model (DOM). Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-18 XSS Targeting Non-Script Elements; CAPEC-198 XSS Targeting Error Pages; CAPEC-199 XSS Using Alternate Syntax; and others. Maps to weaknesses CWE-79, CWE-20, CWE-83.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/588.html
SHA-256 integrity: 98f3a24e633ec324f68e26b1ff8566da3b8bb71ed3e282700f7ce265ffdffb1c
Primary Citations — 10 traced to source
- MITRE CAPEC-588: DOM-Based XSS (https://capec.mitre.org/data/definitions/588.html)
- CWE-79: underlying weakness (http://cwe.mitre.org/data/definitions/79.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.