CVE Database · CVE-2015-9251
CVSS v3.1
N/A
EPSS
29.73%
Published
Jan 18, 2018
Modified
Nov 20, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Weaknesses (CWE)
Affected Products (81)
References (20)
...and 31 more