Cross-Site Scripting in jQuery Prior to 1.9.0 Affects Multiple Applications
CVE-2020-7656

6.1MEDIUM

Key Information:

Vendor
Jquery
Status
Vendor
CVE Published:
19 May 2020

Summary

The jQuery library, specifically versions prior to 1.9.0, is susceptible to Cross-site Scripting (XSS) attacks through its load method. This vulnerability arises because the load method does not adequately sanitize '' HTML tags that contain whitespace characters, such as ''. Consequently, attackers could exploit this flaw to execute arbitrary script code within a user's web browser, potentially leading to data theft or session hijacking. It is critical for developers using jQuery to upgrade their implementations to mitigate this security issue.

Affected Version(s)

jquery All versions prior to version 1.9.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.