Описание
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-18405
- https://br.linkedin.com/in/joas-antonio-dos-santos
- https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4
- https://gitter.im/jquery/jquery?at=5ea844a05cd4fe50a3d7ddc9
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W
- https://twitter.com/DanielRufde/status/1255185961866145792
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 5 лет назад
** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.
redhat
около 5 лет назад
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
CVSS3: 6.1
nvd
около 5 лет назад
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
CVSS3: 6.1
debian
около 5 лет назад
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG ele ...