peter bassill · operator
$ cve CVE-2020-11022 JSON

CVE-2020-11022 EXPLOIT

6.9
MEDIUM · CVSS 3.1 · EPSS 99.2% (pctl 100)

Patch early

A public exploit exists.

Description

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Scoring

CVSS6.9 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS99.22% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2020-04-29
Last modified2026-06-17

Affected (40)

VendorProduct
debiandebian linux
drupaldrupal
fedoraprojectfedora
jqueryjquery
oracleagile product lifecycle management for process
oracleapplication testing suite
oraclebanking digital experience
oracleblockchain platform
oraclecommunications application session controller
oraclecommunications billing and revenue management
oraclecommunications diameter signaling router idih\
oraclecommunications eagle application processor
oraclecommunications services gatekeeper
oraclecommunications webrtc session controller
oracleenterprise manager ops center
oracleenterprise session border controller
oraclefinancial services analytical applications infrastructure
oraclefinancial services analytical applications reconciliation framework
oraclefinancial services asset liability management
oraclefinancial services balance sheet planning
oraclefinancial services basel regulatory capital basic
oraclefinancial services basel regulatory capital internal ratings based approach
oraclefinancial services data foundation
oraclefinancial services data governance for us regulatory reporting
oraclefinancial services data integration hub
oraclefinancial services funds transfer pricing
oraclefinancial services hedge management and ifrs valuations
oraclefinancial services institutional performance analytics
oraclefinancial services liquidity risk management
oraclefinancial services liquidity risk measurement and management
oraclefinancial services loan loss forecasting and provisioning
oraclefinancial services market risk measurement and management
oraclefinancial services price creation and discovery
oraclefinancial services profitability management
oraclefinancial services regulatory reporting for european banking authority
oraclefinancial services regulatory reporting for us federal reserve
oraclehealthcare foundation
oraclehospitality materials control
oraclehospitality simphony
oracleinsurance accounting analyzer

Public exploits

SourceTitleDate
exploit-dbjQuery 1.2 - Cross-Site Scripting (XSS)2021-04-14

References

→ the Explorer  ·  watch your stack  ·  NVD