Cross-Site Scripting in jQuery Prior to 1.9.0 Affects Multiple Applications
CVE-2020-7656
6.1MEDIUM
What is CVE-2020-7656?
The jQuery library, specifically versions prior to 1.9.0, is susceptible to Cross-site Scripting (XSS) attacks through its load method. This vulnerability arises because the load method does not adequately sanitize '' HTML tags that contain whitespace characters, such as ''. Consequently, attackers could exploit this flaw to execute arbitrary script code within a user's web browser, potentially leading to data theft or session hijacking. It is critical for developers using jQuery to upgrade their implementations to mitigate this security issue.
Affected Version(s)
jquery All versions prior to version 1.9.0