From cae326b9ce99d754209ea078fc20df2e48eda58f Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Thu, 29 Oct 2020 16:16:41 +0100 Subject: add link for fix of CVE-2020-26870 --- data/CVE/2020.list | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/2020.list b/data/CVE/2020.list index 98873ecc60..2265c44e9b 100644 --- a/data/CVE/2020.list +++ b/data/CVE/2020.list @@ -2314,6 +2314,7 @@ CVE-2020-26871 CVE-2020-26870 (Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs becaus ...) - dompurify.js NOTE: https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/ + NOTE: https://github.com/cure53/DOMPurify/commit/02724b8eb048dd219d6725b05c3000936f11d62d CVE-2020-26869 (An information exposure vulnerability exists in PcVue 12, allowing a n ...) NOT-FOR-US: PcVue CVE-2020-26868 (A Denial Of Service vulnerability exists in PcVue from version 8.10 on ...) -- cgit v1.2.3