CVE-2020-7656 describes a Cross-site Scripting (XSS) vulnerability in jQuery versions prior to 1.9.0, impacting products like Juniper, NetApp, and Oracle. This flaw allows attackers to execute arbitrary script logic by injecting malformed script tags (e.g., "</script >") that the load method fails to properly sanitize. With a CVSS score of 6.1 (Medium), exploitation requires user interaction (UI:R) but can lead to low confidentiality and integrity impacts (C:L, I:L). While not on the CISA KEV list, an ExploitDB entry (EDB-52141) exists, and there is some community discussion, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.0CPE matchmatch criteria | cpe:2.3:a:jquery:jquery:*:*:*:*:*:node.js:*:* | ||
8.58CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.