Lucene search

K
osvGoogleOSV:CVE-2020-7680
HistoryJul 20, 2020 - 4:15 p.m.

CVE-2020-7680

2020-07-2016:15:12
Google
osv.dev
11
cve-2020-7680
cross-site scripting
docsify.js
fragment identifiers
external urls
javascript/html
security vulnerability

AI Score

6.4

Confidence

High

EPSS

0.03

Percentile

91.0%

docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.

AI Score

6.4

Confidence

High

EPSS

0.03

Percentile

91.0%