CVE-2020-13973: XSS
Published Jun 9, 2020
·Updated
OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be interpreted as JavaScript.
Affected Software
1 affected component
owasp json-sanitizer<1.2.1
Event History
Jun 9, 2020
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-13973.
2
What is the severity of CVE-2020-13973?
The severity of CVE-2020-13973 is medium.
3
What is the affected software for CVE-2020-13973?
The affected software for CVE-2020-13973 is OWASP json-sanitizer before version 1.2.1.
4
What is the CWE ID for CVE-2020-13973?
The CWE ID for CVE-2020-13973 is CWE-79.
5
Is there a fix available for CVE-2020-13973?
Yes, the fix for CVE-2020-13973 is to update to version 1.2.1 or later of OWASP json-sanitizer.