client-side-prototype-pollution icon indicating copy to clipboard operation
client-side-prototype-pollution copied to clipboard

Current latest version of jQuery (3.7.1) prototype pollution

Open halfluke opened this issue 7 months ago • 1 comments

Hello,

I am no good at all with JavaScript, but I noticed that several of your payloads work with jQuery current version - in fact it's mentioned "jQuery all versions". However, other sources state that there are no known vulnerabilities for jQuery 3.7.1. How is that possible, if both DOMInvader and payloads from here work on my target using version 3.7.1? Should a CVE be submitted? Has jQuery decided to "not fix"? I am a bit lost here. Thanks.

halfluke avatar Jul 16 '24 13:07 halfluke