cbcvebase.
CVE-2015-9251
published 2018-01-18

CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Affected

107 ranges· showing 25
VendorProductVersion rangeFixed in
drupalcore>= 8.0.0 < 8.4.58.4.5
drupaldrupal_core
jqueryjquery< 3.0.03.0.0
jqueryjquery>= 0 < 1.12.21.12.2
jqueryjquery>= 0 < 1.12.21.12.2
jqueryjquery>= 1.12.3 < 3.0.03.0.0
jqueryjquery>= 1.12.3 < 3.0.03.0.0
msrcazl3_boost_1.83.0-2_on_azure_linux_3.0
msrcazl3_cal10n_0.8.1.10-1_on_azure_linux_3.0
msrcazl3_ceph_18.2.2-1_on_azure_linux_3.0
msrcazl3_ceph_18.2.2-8_on_azure_linux_3.0
msrcazl3_fontawesome4-fonts_4.7.0-12_on_azure_linux_3.0
msrcazl3_javapackages-bootstrap_1.14.0-2_on_azure_linux_3.0
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0
msrcazl3_openscap_1.3.9-1_on_azure_linux_3.0
msrcazl3_orangefs_2.9.8-3_on_azure_linux_3.0
msrcazl3_python-blinker_1.7.0-4_on_azure_linux_3.0
msrcazl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_scons_4.6.0-1_on_azure_linux_3.0
msrcazl3_slf4j_1.7.30-6_on_azure_linux_3.0
msrcazl3_slf4j_2.0.7-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vulncheck6.1MEDIUM