CVE-2018-18405: XSS
DISPUTED jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18405?
The severity of CVE-2018-18405 is medium with a CVSS score of 6.1.
How does the vulnerability in jQuery v2.2.2 allow XSS?
The vulnerability in jQuery v2.2.2 allows XSS by exploiting a crafted onerror attribute of an IMG element.
Is the reported vulnerability in jQuery v2.2.2 confirmed?
The reported vulnerability in jQuery v2.2.2 is disputed and reported to be a spam entry.
How can I mitigate the vulnerability in jQuery v2.2.2?
To mitigate the vulnerability in jQuery v2.2.2, consider upgrading to a patched version of jQuery or using an alternative library.
Where can I find more information about CVE-2018-18405?
More information about CVE-2018-18405 can be found at the following references: - [Reference 1](https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4) - [Reference 2](https://gitter.im/jquery/jquery?at=5ea844a05cd4fe50a3d7ddc9) - [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W/)