CVSS v3
6.1
MEDIUM
EPSS Score
7.2 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Technical details
- Published
- 2020-04-29
- Exploit-DB
- EDB-49766
Frequently asked questions
What is CVE-2020-11022?
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Is CVE-2020-11022 actively exploited?
Active exploitation of CVE-2020-11022 has not been confirmed. The EPSS score is 7.2%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-11022?
CVE-2020-11022 has a CVSS v3 base score of 6.1 (MEDIUM severity).
Is CVE-2020-11022 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).