** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.
References
Configurations
Information
Published : 2020-04-22 11:15
Updated : 2020-05-30 23:15
NVD link : CVE-2018-18405
Mitre link : CVE-2018-18405
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
jquery
- jquery