CVE-2020-7656
19.05.2020, 21:15
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
Vendor | Product | Version |
---|---|---|
jquery | jquery | 𝑥 < 1.9.0 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | oncommand_system_manager | 3.0.0 ≤ 𝑥 ≤ 3.1.3 |
netapp | snap_creator_framework | - |
juniper | junos | 21.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References