jQuery – XSS Vulnerability Under 3.0.0, When Making Cross-Domain Calls Without The dataType Option

< 1 min read

Impact Area

Security

 

 

 

Severity

High

 

 

 

Affected Element

ServiceNow

UI Script

Salesforce

Static Resource

Rule number

SN-JSL-013 (for ServiceNow)

SF-JSL-013 (for Salesforce)

Impact #

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Remediation #

Update jQuery to the latest version.

Time to fix #

30 min

Updated on March 21, 2025
Table of contents
Was it helpful ?