← לוח פגיעויות

CVE-2020-11023

בינונית 6.1 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
JQuery Cross-Site Scripting (XSS) Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

מדדים

CVSS 3.1
6.1 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS — סבירות ניצול
84% (אחוזון 100) נכון ל-31/7/2026
CWE
CWE-79

מוצרים מושפעים

jquery: jquery; debian: debian linux; fedoraproject: fedora; drupal: drupal; oracle: application express; oracle: application testing suite; oracle: banking enterprise collections; oracle: banking platform; oracle: blockchain platform; oracle: business intelligence; oracle: communications analytics; oracle: communications eagle application processor; oracle: communications element manager; oracle: communications interactive session recorder; oracle: communications operations monitor

קישורים