CVE-2020-11023 - JQuery Cross-Site Scripting (XSS) Vulnerability
Project:JQuery
Product:JQuery
Date Added:2025-01-23Due Date:2025-02-13
Vulnerability Name
JQuery Cross-Site Scripting (XSS) Vulnerability
Description
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
https://nvd.nist.gov/vuln/detail/CVE-2020-11023
Related News Articles
CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities ListJanuary 24, 2025