Reported May 25, 2013 | Resolved June 2013
High (Verified)DOM XSS
jQuery V1.7
Parameter location.hash via <svg onload="alert('Vulnerable jQuery V1.7')">
Other information CWE-79:Type0: In DOM-based XSS, the client performs the injection of XSS into the page; in the other types, the server performs the injection. DOM-based XSS generally involves server-controlled, trusted script that is sent to the client, such as Javascript that performs sanity checks on a form before the user submits it. If the server-supplied script processes user-supplied data and then injects it back into the web page (such as with dynamic HTML), then DOM-based XSS is possible.

