peter bassill · operator
$ cve CVE-2020-11023 JSON

CVE-2020-11023 KEV EXPLOIT

6.9
MEDIUM · CVSS 3.1 · EPSS 84.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-02-13.

Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Scoring

CVSS6.9 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS84.89% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-79
On CISA KEVyes — remediate by 2025-02-13
Public exploityes
Published2020-04-29
Last modified2026-06-17

CISA KEV

NameJQuery Cross-Site Scripting (XSS) Vulnerability
Added2025-01-23
Due2025-02-13
Vendor / productJQuery / JQuery
Ransomware usenone reported

Affected (40)

VendorProduct
debiandebian linux
drupaldrupal
fedoraprojectfedora
jqueryjquery
netapph300s
netapph300s firmware
netapph500s
netapph500s firmware
netapph700s
netapph700s firmware
oracleapplication express
oracleapplication testing suite
oraclebanking enterprise collections
oraclebanking platform
oracleblockchain platform
oraclebusiness intelligence
oraclecommunications analytics
oraclecommunications eagle application processor
oraclecommunications element manager
oraclecommunications interactive session recorder
oraclecommunications operations monitor
oraclecommunications services gatekeeper
oraclecommunications session report manager
oraclecommunications session route manager
oraclefinancial services regulatory reporting for de nederlandsche bank
oraclefinancial services revenue management and billing analytics
oraclehealth sciences inform
oraclehealthcare translational research
oraclehyperion financial reporting
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oracleoss support tools
oraclepeoplesoft enterprise human capital management resources
oracleprimavera gateway
oraclerest data services
oraclesiebel mobile
oraclestoragetek acsls
oraclestoragetek tape analytics sw tool
oraclewebcenter sites
oracleweblogic server

Public exploits

SourceTitleDate
exploit-dbjQuery 1.0.3 - Cross-Site Scripting (XSS)2021-04-14

References

→ the Explorer  ·  watch your stack  ·  NVD