CVE-2020-7656 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 6.3% (pctl 93)
Patch early
A public exploit exists.
Description
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 6.27% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-05-19 |
| Last modified | 2026-06-17 |
Affected (7)
| Vendor | Product |
|---|---|
| jquery | jquery |
| juniper | junos |
| netapp | active iq unified manager |
| netapp | cloud backup |
| netapp | oncommand system manager |
| netapp | snap creator framework |
| oracle | peoplesoft enterprise peopletools |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | jQuery 3.3.1 - Prototype Pollution & XSS Exploit | 2025-04-08 |
References
- https://security.netapp.com/advisory/ntap-20200528-0001/
- https://snyk.io/vuln/SNYK-JS-JQUERY-569619
- https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1?language=en_US
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20200528-0001/
- https://snyk.io/vuln/SNYK-JS-JQUERY-569619
- https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1?language=en_US
- https://www.oracle.com/security-alerts/cpujul2022.html
→ the Explorer · watch your stack · NVD