6.1
CVSSv3

CVE-2020-26870

Published: 07/10/2020 Updated: 27/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cure53 DOMPurify prior to 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cure53 dompurify

debian debian linux 9.0

microsoft visual studio 2017 15.9

microsoft visual studio 2019 16.0

microsoft visual studio 2019 16.4

microsoft visual studio 2019 16.8

microsoft visual studio 2019 16.7

oracle application express