CVE-2020-6802
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
- Mozilla Bleach
- < 3.1.1
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2020-03-24
CVE-2020-6802 at NVD
1 known exploit for CVE-2020-6802
Proof-of-concept code and exploit modules indexed by Sploitus