First published: Mon Jun 21 2021(Updated: )
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prototype JavaScript Framework | =1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27511 has been classified as a medium severity vulnerability.
To fix CVE-2020-27511, upgrade the Prototype JavaScript Framework to a version beyond 1.7.3.
Exploiting CVE-2020-27511 can lead to a Regular Expression Denial of Service (ReDOS), potentially degrading application performance.
Yes, if your application uses Prototype 1.7.3, it is at risk due to the vulnerability found in stripTags and unescapeHTML components.
CVE-2020-27511 affects the stripTags and unescapeHTML components of the Prototype JavaScript Framework.