CVE-2018-18405
MEDIUMjQuery 2.2.2 - Cross-Site Scripting via IMG onerror Attribute
Title source: llmDescription
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
References (4)
Core 4
Core References
Various Sources x_refsource_misc
https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4
Various Sources x_refsource_misc
https://twitter.com/DanielRufde/status/1255185961866145792
Various Sources x_refsource_misc
https://gitter.im/jquery/jquery?at=5ea844a05cd4fe50a3d7ddc9
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W/
Scores
CVSS v3
6.1
EPSS
0.0162
EPSS Percentile
73.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
jquery/jquery
2.2.2
Published
Apr 22, 2020
Tracked Since
Feb 18, 2026