CVE-2020-7656
PoC —CVSS 3.1
6.1 medium
EPSS
6%p93
Published
()
Modified
Description
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove " " HTML tags that contain a whitespace character, i.e: " ", which results in the enclosed script logic to be executed.
In the news0 stories
No ingested article mentions this CVE yet.