cbcvebase.
CVE-2020-26870
published 2020-10-07

CVE-2020-26870: Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

Affected

20 ranges
VendorProductVersion rangeFixed in
ammonia_projectammonia< 3.1.03.1.0
ammonia_projectammonia>= 0 < 2.1.32.1.3
ammonia_projectammonia>= 3.0.0 < 3.1.03.1.0
cure53dompurify< 2.0.172.0.17
cure53dompurify>= 0 < 2.0.172.0.17
debiandebian_linux
debianrust-ammonia< rust-ammonia 3.1.2-1 (bookworm)rust-ammonia 3.1.2-1 (bookworm)
github.comgotify_server>= 0 < 2.2.32.2.3
marktextmarktext<= 0.16.2
microsoftvisual_studio_2017
microsoftvisual_studio_2019
microsoftvisual_studio_2019
microsoftvisual_studio_2019
microsoftvisual_studio_2019
msrcmicrosoft_visual_studio_2017_version_15.9
msrcmicrosoft_visual_studio_2019_version_16.0
msrcmicrosoft_visual_studio_2019_version_16.4
msrcmicrosoft_visual_studio_2019_version_16.7
msrcmicrosoft_visual_studio_2019_version_16.8
oracleapplication_express< 21.1.0.00.0121.1.0.00.01

CVSS provenance

nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
ghsa6.1MEDIUM
osv6.1MEDIUM