Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-5848 Vulnerability (CVE-2013-5848)
Contao Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10641)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-3809)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (7.9.0)