6.1
CVSSv3

CVE-2020-23064

Published: 26/06/2023 Updated: 01/04/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cross Site Scripting vulnerability in jQuery 2.2.0 up to and including 3.x prior to 3.5.0 allows a remote malicious user to execute arbitrary code via the <options> element.

Vulnerable Product Search on Vulmon Subscribe to Product

jquery jquery

netapp cloud backup -

netapp active iq unified manager -

netapp management services for element software and netapp hci -

netapp brocade san navigator -

netapp virtual desktop service -

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Cross Site Scripting vulnerability in jQuery 220 through 3x before 350 allows a remote attacker to execute arbitrary code via the &amp;lt;options&amp;gt; element ...

Recent Articles

Chinese government website security is often worryingly bad, say Chinese researchers
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Bad configurations, insecure versions of jQuery, and crummy cookies are some of myriad problems

Exclusive Five Chinese researchers examined the configurations of nearly 14,000 government websites across the country and found worrying lapses that could lead to malicious attacks, according to a not-yet-peer-reviewed study released last week. The authors, all from the Harbin Institute of Technology, described the study as scrutinizing "the security and dependency challenges besieging China's governmental web infrastructure." They claim to have revealed "substantial vulnerabilities and depende...