Lucene search

K
cvelistSnykCVELIST:CVE-2020-7676
HistoryJun 08, 2020 - 1:34 p.m.

CVE-2020-7676

2020-06-0813:34:09
snyk
www.cve.org
2

5.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.9%

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping “<option>” elements in “<select>” ones changes parsing behavior, leading to possibly unsanitizing code.

CNA Affected

[
  {
    "product": "angular.js",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to 1.8.0"
      }
    ]
  }
]

References

5.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.9%