Home / Vulnerability Database / TypeScript : Cross-domain requests allowed for JQuery Mobile
TypeScript
TypeScript : Cross-domain requests allowed for JQuery Mobile
Classification
OWASP Top 10 2017
OWASP Top 10 2021
Overview
Cross-domain requests are allowed for JQuery Mobile.
When jQuery Mobile attempts to load an external page, the request runs through $.mobile.loadPage().
Because the jQuery Mobile framework tracks what page is being viewed within the browser location hash, it is possible for a cross-site scripting (XSS) attack to occur if the XSS code in question can manipulate the hash and set it to a cross-domain URL of its choice.
This is the main reason that the default setting for $.mobile.allowCrossDomainPages is set to false.
MEDIUM
DerScanner Severity Score
Do you want to fix TypeScript : Cross-domain requests allowed for JQuery Mobile in your application?
See also
TypeScript
TypeScript : Unsafe Azure access control
TypeScript
TypeScript : Debug code
TypeScript
