CVE-2020-7690: XSS
Published Jul 6, 2020
·Updated
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It's possible to inject JavaScript code via the html method.
Other sources
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
Affected Software
2 affected componentsFixes available
npm/jspdf<2.0.0
2.0.0
parall jspdf Node.js<2.0.0
Event History
Jul 6, 2020
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
DescriptionWeakness
May 17, 2021
Advisory Published
09:01 PM
Frequently Asked Questions
1
What is the vulnerability ID for this package vulnerability?
The vulnerability ID for this package vulnerability is CVE-2020-7690.
2
What is the severity of CVE-2020-7690?
The severity of CVE-2020-7690 is medium, with a severity value of 6.1.
3
What is the description of CVE-2020-7690?
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It's possible to inject JavaScript code via the `html` method.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by injecting JavaScript code via the `html` method.
5
What is the remedy for CVE-2020-7690?
The remedy for CVE-2020-7690 is to update to version 2.0.0 of the jspdf package.