CVE-2015-9251
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
- Affected products
- Almalinux, Centos, Oracle Weblogic Server, Red Hat, Rocky Linux, Suse, Jquery
- Jquery
- < 3.0.0
- Fix
- Available
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 29.7% (98th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2018-01-18
CVE-2015-9251 at NVD
2 known exploits for CVE-2015-9251
Proof-of-concept code and exploit modules indexed by Sploitus