ZeroHour

CVE-2020-7656

PoC
CVSS 3.1
6.1 medium
EPSS
6%p93
Published
()
Modified
Description

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove " " HTML tags that contain a whitespace character, i.e: " ", which results in the enclosed script logic to be executed.

Vendors
jqueryoraclenetappjuniper
Products
jquery, peoplesoft enterprise peopletools, active iq unified manager, cloud backup, oncommand system manager, snap creator framework, junos
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.