First published: Wed Apr 22 2020(Updated: )
** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jquery Jquery | =2.2.2 | |
=2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18405 is medium with a CVSS score of 6.1.
The vulnerability in jQuery v2.2.2 allows XSS by exploiting a crafted onerror attribute of an IMG element.
The reported vulnerability in jQuery v2.2.2 is disputed and reported to be a spam entry.
To mitigate the vulnerability in jQuery v2.2.2, consider upgrading to a patched version of jQuery or using an alternative library.
More information about CVE-2018-18405 can be found at the following references: - [Reference 1](https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4) - [Reference 2](https://gitter.im/jquery/jquery?at=5ea844a05cd4fe50a3d7ddc9) - [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W/)