Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-104 — Cross Zone Scripting
CAPEC-104

Cross Zone Scripting

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An attacker is able to cause a victim to load content into their web-browser that bypasses security zone controls and gain access to increased privileges to execute scripting code or other web objects such as unsigned ActiveX controls or applets. This is a privilege elevation attack targeted at zone-based web-browser security.

Mitigation

Disable script execution. | Ensure that sufficient input validation is performed for any potentially untrusted data before it is used in any privileged context or zone | Limit the flow of untrusted data into the privileged areas of the system that run in the higher trust zone | Limit the sites that are being added to the local machine zone and restrict the privileges of the code running in that zone to the bare minimum | Ensure proper HTML output encoding before writing user supplied data to the page

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.