This repository was archived by the owner on Oct 8, 2021. It is now read-only.
- Notifications
You must be signed in to change notification settings - Fork2.4k
This repository was archived by the owner on Oct 8, 2021. It is now read-only.
XSS with XHR level2 cross domain request #1990
Closed
Milestone
Description
jQuery mobile can load other domain's html.
All version of jQuery mobile has security risk, it can XSS or display fake contents.
example:
http://jquerymobile.com/demos/1.0b1/#http://ma.la/tmp/jquerymobiletest.html