Home / Vulnerability Database / TypeScript : Cross-domain requests allowed for JQuery Mobile
TypeScript

TypeScript : Cross-domain requests allowed for JQuery Mobile

Classification

Overview

Cross-domain requests are allowed for JQuery Mobile.

When jQuery Mobile attempts to load an external page, the request runs through $.mobile.loadPage(). Because the jQuery Mobile framework tracks what page is being viewed within the browser location hash, it is possible for a cross-site scripting (XSS) attack to occur if the XSS code in question can manipulate the hash and set it to a cross-domain URL of its choice. This is the main reason that the default setting for $.mobile.allowCrossDomainPages is set to false.

MEDIUM

DerScanner Severity Score

Do you want to fix TypeScript : Cross-domain requests allowed for JQuery Mobile in your application?

See also

TypeScript

TypeScript : Unsafe Azure access control

TypeScript

TypeScript : Debug code

TypeScript

TypeScript : XSS protection is disabled