Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-1000229. PoCs published by barteeees.
AI-analyzed exploit summary The repository contains two YAML files demonstrating a Cross-Site Scripting (XSS) vulnerability in SwaggerUI (CVE-2016-1000229). The exploit leverages maliciously crafted SVG and HTML payloads embedded in the Swagger API specification to trigger XSS when rendered by the SwaggerUI interface.
Description
swagger-ui has XSS in key names
Exploits (1)
The repository contains two YAML files demonstrating a Cross-Site Scripting (XSS) vulnerability in SwaggerUI (CVE-2016-1000229). The exploit leverages maliciously crafted SVG and HTML payloads embedded in the Swagger API specification to trigger XSS when rendered by the SwaggerUI interface.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N