← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-7656

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

No Active Exploit Signals
CVSS Base Score
6.1
MEDIUM
EPSS Probability:6.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
jquery jquery all
oracle peoplesoft_enterprise_peopletools 8.58
netapp active_iq_unified_manager all
netapp cloud_backup all
netapp oncommand_system_manager all
netapp snap_creator_framework all
juniper junos 21.2

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
6.273%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySnyk · Open Source · UK
Reserved2020-01-21T00:00:00
Published2020-05-19T00:00:00
Last Updated2024-08-04T09:33:19

LINK COPIED TO CLIPBOARD