mirror of
https://github.com/jokob-sk/NetAlertX.git
synced 2026-04-02 00:02:19 -07:00
Merge pull request #1582 from navnitan-7/fix/cve-2015-9251-jquery-ajax
Some checks are pending
Some checks are pending
Potential Vulnerability in Cloned Code
This commit is contained in:
@@ -9059,6 +9059,11 @@ function ajaxConvert( s, response, jqXHR, isSuccess ) {
|
||||
// Convert response if prev dataType is non-auto and differs from current
|
||||
} else if ( prev !== "*" && prev !== current ) {
|
||||
|
||||
// Mitigate possible XSS vulnerability (gh-2432)
|
||||
if ( s.crossDomain && current === "script" ) {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Seek a direct converter
|
||||
conv = converters[ prev + " " + current ] || converters[ "* " + current ];
|
||||
|
||||
|
||||
Reference in New Issue
Block a user