CVE-2020-8823
Summary
| CVE | CVE-2020-8823 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-10 03:15:00 UTC |
| Updated | 2021-01-12 16:01:00 UTC |
| Description | htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| GitHub - theyiyibest/Reflected-XSS-on-SockJS |
MISC |
github.com |
Exploit, Patch, Third Party Advisory |
| Cross-site Scripting (XSS) in sockjs | Snyk |
MISC |
snyk.io |
Third Party Advisory |
| sockjs/sockjs-client · GitHub |
MISC |
www.sockjs.org |
Vendor Advisory |
| Affected version and product name accurate? · Issue #1 · theyiyibest/Reflected-XSS-on-SockJS · GitHub |
MISC |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982755 Nodejs (npm) Security Update for sockjs (GHSA-hh8v-jmh3-9437)