Skip to content
COOEY

EXPOSURES › CVE-2020-11023

CVE-2020-11023

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-01-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11023 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

JQuery's DOM manipulators execute untrusted code when processing malicious HTML input, enabling XSS attacks.

JQuery's DOM manipulation functions allow execution of untrusted code when processing malicious HTML input, creating a persistent XSS vulnerability that can compromise browser contexts. DIB organizations must audit all JQuery usage in FedRAMP systems and apply vendor patches immediately to prevent credential theft or session hijacking.

Shame score — A known XSS vulnerability in a widely-used library that requires vendor patching rather than representing a supply-chain default credential failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.