KEVIntel
6.9
CVSS
Medium

CVE-2020-11023

PUBLISHED

Potential XSS vulnerability in jQuery

Exploited in the wild Remote
Vendor
jquery
Product
jQuery
Published
Apr 29, 2020
EPSS

Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

cisa nessus_scanner

CVSS scores

CVSS v3.1 6.9 Medium

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Exploitation status

Exploited in the wild

Recorded 2025-01-23 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
partial

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 23, 2025

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/236419 Jun 02, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Cybernegro/CVE-2020-11023

github · Created 2024-01-03 02:35:37 UTC · 2 stars

CVE-2020-11023 PoC for bug bounty.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus