Skip to content
This repository was archived by the owner on Oct 8, 2021. It is now read-only.

jQuery Mobile XSS Problem #1789

Closed
wants to merge 1 commit into from
Closed

Conversation

Image for: Conversation
Copy link

jnlin commented Jun 6, 2011

Demo: http://jquerymobile.com/demos/1.0a4.1/#<img src=/ss onerror={alert('yy');}>

I am not sure if the patch is perfect, but it works for me.

Copy link

Thanks! Looks like this is fixed in latest though, so I guess our navigation refactor covered it. Example here: http://jquerymobile.com/test/#<img src=/ss onerror={alert('yy');}>

Let me know if you still see the issue anywhere. Thanks!

scottjehl closed this Jun 9, 2011
Copy link
Author

jnlin commented Jun 14, 2011

It works, thank you :)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
2 participants