Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
https-nj.gov---CVE-2020-11023 — Vulnearability Report of the New Jersey official site | Kitploit
Tools/GitHubGitHub/snorlyd/https-nj.gov---cve-2020-11023
Vulnerability AnalysisCode AnalysisWeb SecurityPapers & ResearchLearning & Education
GitHubsnorlyd/https-nj.gov---cve-2020-11023

https-nj.gov---CVE-2020-11023

Vulnearability Report of the New Jersey official site

View Repository
134 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

https-nj.gov---CVE-2020-11023

Vulnearability Report of the New Jersey official site

Potential XSS vulnerability when appending HTML containing option elements.

Passing HTML containing <option> elements from untrusted sources - even after sanitizing them - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.

RECOMMENDATION

This problem is patched in jQuery 3.5.0; Therefore, it would only be necessary to update it. To fix this bug without updating it, we can use DOMPurify with its SAFE_FOR_JQUERY option to sanitize the HTML string before passing it to a jQuery method.

At least jQuery 1.12/2.2 or later is required to apply this workaround.

REFERENCES

https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/

For more information

If you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue.

Download Tool