VDB
BDU%3A2021-00576
BDU%3A2021-00576
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Уязвимость библиотеки DOMPurify, связанная с непринятием мер по защите структуры веб-старницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку
Risk Scores
CVSS 2.0
5.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Microsoft Corp, Cure53 | Debian GNU/Linux, Microsoft Visual Studio 2019, DOMPurify, Microsoft Visual Studio 2017 |
Timeline
- Feb 8, 2021 CVE Published
- Mar 19, 2026 Security Advisory
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-26870 url
- https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/ url
- https://github.com/cure53/DOMPurify/commit/02724b8eb048dd219d6725b05c3000936f11d62d url
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-26870 advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00029.html advisory