Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
MEDIUM 6.1 npm

Cross-Site Scripting in jquery

GHSA-2pqj-h3vj-pqgw · CVE-2012-6708

Published · Modified

Description

Affected versions of jquery are vulnerable to cross-site scripting. This occurs because the main jquery function uses a regular expression to differentiate between HTML and selectors, but does not properly anchor the regular expression. The result is that jquery may interpret HTML as selectors when given certain inputs, allowing for client side code execution.

Proof of Concept

$("#log").html(
    $("element[attribute='<img src=\"x\" onerror=\"alert(1)\" />']").html()
);

Recommendation

Update to version 1.9.0 or later.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes