Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.116
EPSS Ranking 93.3%
CVSS Severity
CVSS v3 Score 6.9
CVSS v2 Score 4.3
Proposed Action
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.
Ransomware Campaign
Unknown
References
Products affected by CVE-2020-11023


Contact Us

Shodan ® - All rights reserved