CVE-2020-7656
19.05.2020, 21:15
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
| Vendor | Product | Version |
|---|---|---|
| jquery | jquery | 𝑥 < 1.9.0 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | cloud_backup | - |
| netapp | oncommand_system_manager | 3.0.0 ≤ 𝑥 ≤ 3.1.3 |
| netapp | snap_creator_framework | - |
| juniper | junos | 21.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References