client-side-prototype-pollution
client-side-prototype-pollution copied to clipboard
Current latest version of jQuery (3.7.1) prototype pollution
Hello,
I am no good at all with JavaScript, but I noticed that several of your payloads work with jQuery current version - in fact it's mentioned "jQuery all versions". However, other sources state that there are no known vulnerabilities for jQuery 3.7.1. How is that possible, if both DOMInvader and payloads from here work on my target using version 3.7.1? Should a CVE be submitted? Has jQuery decided to "not fix"? I am a bit lost here. Thanks.