jQuery - XSS vulnerability under 3.5.0, when using htmlPrefilter

Impact area

Security

Severity

High

Affected element

ServiceNow

UI Script

Salesforce

Static Resource


Rule number

SN-JSL-001 (for ServiceNow)

SF-JSL-001 (for Salesforce)

Impact

Increased vulnerability to cross-site scripting attacks.

Remediation

Update jQuery to the latest version.

Time to fix

30 min

References

This rule is linked to Common Weakness Enumeration CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').




Last modified on Aug 19, 2020