QID 730869
Date Published: 2023-08-22
QID 730869: jQuery Cross-Site Scripting (XSS)Vulnerability
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Affected Versions:
jQuery versions before 3.0
QID Detection Logic (un-Authenticated):
This QID checks version of jquery.js file
On successful exploitation is allows an attacker to execute xss attack.
Solution
The vendor has released a fix to resolve the vulnerability. Refer to jQuery downloads to obtain additional details.
Vendor References
- jquery -
github.com/jquery/jquery/issues/2432
CVEs related to QID 730869
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| jQuery |
|