// For flags

CVE-2020-26870

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

Cure53 DOMPurify versiones anteriores a 2.0.17, permite una mutación de XSS. Esto ocurre porque un viaje de ida y vuelta de análisis serializado no necesariamente devuelve el árbol DOM original, y un espacio de nombres puede cambiar de HTML a MathML, como es demostrado al anidar los elementos FORM

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-10-07 CVE Reserved
  • 2020-10-07 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-09-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cure53
Search vendor "Cure53"
Dompurify
Search vendor "Cure53" for product "Dompurify"
< 2.0.17
Search vendor "Cure53" for product "Dompurify" and version " < 2.0.17"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio 2017
Search vendor "Microsoft" for product "Visual Studio 2017"
15.9
Search vendor "Microsoft" for product "Visual Studio 2017" and version "15.9"
-
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio 2019
Search vendor "Microsoft" for product "Visual Studio 2019"
16.0
Search vendor "Microsoft" for product "Visual Studio 2019" and version "16.0"
-
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio 2019
Search vendor "Microsoft" for product "Visual Studio 2019"
16.4
Search vendor "Microsoft" for product "Visual Studio 2019" and version "16.4"
-
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio 2019
Search vendor "Microsoft" for product "Visual Studio 2019"
16.7
Search vendor "Microsoft" for product "Visual Studio 2019" and version "16.7"
-
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio 2019
Search vendor "Microsoft" for product "Visual Studio 2019"
16.8
Search vendor "Microsoft" for product "Visual Studio 2019" and version "16.8"
-
Affected
Oracle
Search vendor "Oracle"
Application Express
Search vendor "Oracle" for product "Application Express"
< 21.1.0.00.01
Search vendor "Oracle" for product "Application Express" and version " < 21.1.0.00.01"
-
Affected