Lucene search

K
f5F5F5:K32412075
HistoryJul 23, 2021 - 12:00 a.m.

K32412075 : AngularJS XSS vulnerability CVE-2020-7676

2021-07-2300:00:00
my.f5.com
51

5.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.9%

Security Advisory Description

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping “<option>” elements in “<select>” ones changes parsing behavior, leading to possibly unsanitizing code. (CVE-2020-7676)

Impact

An attacker may exploit this vulnerability to perform a cross-site scripting (XSS) attack.

5.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.9%