PT-2012-1248 · Jquery+2 · Jquery+2
Timmywil
·
Published
2012-02-06
·
Updated
2026-02-18
·
CVE-2012-6708
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
jquery versions prior to 1.9.0
Description
The issue is related to the jQuery function not properly differentiating between HTML and selectors, allowing for cross-site scripting attacks. In vulnerable versions, jQuery determines whether the input is HTML by looking for the '<' character anywhere in the string, giving attackers flexibility when constructing a malicious payload. This can lead to client-side code execution. The estimated number of potentially affected devices is not specified.
Recommendations
Update to version 1.9.0 or later. As a temporary workaround, consider restricting the use of the vulnerable
jquery function until a patch is available. Avoid using the jquery function with untrusted input to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Ubuntu
Jquery