Reflected cross-site scripting (XSS) In jquery-rails

Description

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). load() fails to recognize and remove script HTML tags that contain a whitespace character, i.e: which results in the enclosed script logic to be executed. This can lead to Cross-site Scripting attacks when an attacker has control of the enclosed script.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions

1-10 of 16

10