Lucene search

K
f5F5F5:K62532311
HistoryNov 28, 2018 - 12:00 a.m.

K62532311 : jQuery vulnerability CVE-2012-6708

2018-11-2800:00:00
my.f5.com
162

AI Score

5.8

Confidence

High

EPSS

0.008

Percentile

82.0%

Security Advisory Description

jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the ‘<’ character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the ‘<’ character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common. (CVE-2012-6708)

Impact

This vulnerability allows an authenticated user to perform an unauthorized modification.