jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JS-JQUERY-569619 | Exploit Third Party Advisory |
https://security.netapp.com/advisory/ntap-20200528-0001/ | |
https://www.oracle.com/security-alerts/cpujul2022.html |
Configurations
Information
Published : 2020-05-19 14:15
Updated : 2022-07-25 11:15
NVD link : CVE-2020-7656
Mitre link : CVE-2020-7656
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
jquery
- jquery