Cross-Site Scripting via JSONP
Moderate severity
GitHub Reviewed
Published
Jun 27, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 27, 2019
Published to the GitHub Advisory Database
Jun 27, 2019
Last updated
Jan 9, 2023
JSONP allows untrusted resource URLs, which provides a vector for attack by malicious actors.
References