CVE-2020-7656

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-7656
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7656.json
Aliases
Related
Published
2020-05-19T21:15:10Z
Modified
2023-11-08T04:04:03.117901Z
Details

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.

References

Affected packages

Git / github.com/jquery/jquery

Affected ranges

Type
GIT
Repo
https://github.com/jquery/jquery
Events
Introduced
0The exact introduced commit is unknown
Fixed