QID 730499
QID 730499: jQuery Prior to 1.9.0 Cross-Site Scripting Vulnerability
jquery prior allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<SCRIPT>" HTML tags that contain a whitespace character, i.e: "</SCRIPT>", which results in the enclosed script logic to be executed.
Affected Versions:
jQuery Versions prior to 1.9.0 are affected.
Exploitation could allow remote attackers to conduct cross-site scripting attacks.
Solution
The vendor has released a fix to resolve the vulnerability. Refer to jQuery 1.9.0 Release Notes to obtain additional details.
Vendor References
CVEs related to QID 730499
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| jQuery 1.9.0 | jQuery |
|