jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
2020-05-19T21:15:10.257
2024-11-21T05:37:33.227
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jquery | jquery | < 1.9.0 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.58 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | oncommand_system_manager | ≤ 3.1.3 | Yes |
Application | netapp | snap_creator_framework | - | Yes |
Operating System | juniper | junos | 21.2 | Yes |