cve-2020-11023

HIGH cisa_known_exploited
Description

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

Timeline
Published
2025-01-23
Last Modified
2025-01-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

{
  "cvss": 0.0,
  "datePublished": "2025-01-23",
  "dateUpdated": "2025-01-23",
  "description": "JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.",
  "dueDate": "2025-02-13",
  "id": "CVE-2020-11023",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 ; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2020-11023",
  "product": "JQuery",
  "requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "severity": "HIGH",
  "source": "cisa_known_exploited",
  "title": "JQuery Cross-Site Scripting (XSS) Vulnerability",
  "vendor": "JQuery"
}
View JSON API Download JSON