Cross-site scripting in DOMPurify - CVE-2020-26870
Published: October 7, 2020 / Updated: April 18, 2023
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Cure53 DOMPurify. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Swagger UI
Web Help Desk
Visual Studio
Oracle Retail Customer Management and Segmentation Foundation
Database Performance Analyzer
Oracle Application Express
How to mitigate CVE-2020-26870
Swagger UI - update to 3.37.0
Web Help Desk - update to 12.8.4
Database Performance Analyzer - update to 2023.2
Oracle Application Express - update to 21.1.0.00.01
External References
Related Security Bulletins
- Remote code execution in Microsoft Visual Studio
- Multiple vulnerabilities in Oracle Application Express
- Cross-site scripting in Cure53 DOMPurify
- Reflected XSS in SwaggerUI DOMPurify component
- Multiple vulnerabilities in SolarWinds Database Performance Analyzer
- Multiple vulnerabilities in Oracle Retail Customer Management and Segmentation Foundation
- Multiple vulnerabilities in SolarWinds Web Help Desk