On this page

Atomicorp WAF Rule 340112

Rule Summary

  • Rule ID: 340112
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: cross site scripting attempt to execute Javascript code
  • Observed CWEs: CWE-79 (8)
  • Revision: 3
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request URI, Request headers
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects when a client is attempting to inject javascript via either an untrusted argument, untrusted application or both. This may be a cross site scripting attack.

Troubleshooting

False Positives

If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Do not disable this rule.

Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2018-5230Atlassian Jira Confluence - Cross-Site Scriptingjira6.1 (v3.0)Medium
CVE-2019-14974SugarCRM Enterprise 9.0.0 - Cross-Site Scriptingsugarcrm6.1 (v3.0)Medium
CVE-2021-43810Admidio - Cross-Site Scriptingadmidio6.1 (v3.1)Medium
CVE-2022-0437karma-runner DOM-based Cross-Site Scriptingkarma6.1 (v3.1)Medium
CVE-2022-0653Wordpress Profile Builder Plugin Cross-Site Scriptingprofile builder6.1 (v3.1)Medium
CVE-2024-28734Coda v.2024Q1 - Cross-Site ScriptingUnit4 Financials by Coda prior to 2023Q46.1 (v3.1)Medium
CVE-2026-25616Blesta <= 5.13.1 - Cross-Site Scriptingblesta6.1 (v3.1)Medium
CVE-2026-55592Dashy <= 4.3.6 - Reflected XSS via Workspacedashy3.9 (v3.1)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-79CVE-2018-5230 , CVE-2019-14974 , CVE-2021-43810 , CVE-2022-0437 , CVE-2022-0653 , CVE-2024-28734 , CVE-2026-25616 , CVE-2026-55592

Documentation Source

  • Original wiki page: WAF 340112
  • Source revision: 6064
  • Source revision date: 2020-08-24