CVE Vulnerabilities

CVE-2020-36827

Incomplete Filtering of Special Elements

Published: Mar 24, 2024 | Modified: Mar 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.

Weakness

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

References