Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-245 — XSS Using Doubled Characters
CAPEC-245

XSS Using Doubled Characters

TLP:CLEAR

Description

Typical severity: Medium. The adversary bypasses input validation by using doubled characters in order to perform a cross-site scripting attack. Some filters fail to recognize dangerous sequences if they are preceded by repeated characters. For example, by doubling the < before a script command, (

Mitigation

Design: Use libraries and templates that minimize unfiltered input. | Implementation: Normalize, filter and sanitize all user supplied fields. | Implementation: The victim should configure the browser to minimize active content from untrusted sources.

Details

Platforms
Software
Software
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.