From cd8aeece3a3dea9201b93ce606c8d9ed5d2475a8 Mon Sep 17 00:00:00 2001 From: npt-1707 Date: Mon, 18 May 2026 06:50:34 +0800 Subject: [PATCH] web-gui/buildyourownbotnet/assets/js/datatables/jQuery-1.11.3/jquery-1.11.3.js: Ajax: Mitigate possible XSS vulnerability --- .../assets/js/datatables/jQuery-1.11.3/jquery-1.11.3.js | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/web-gui/buildyourownbotnet/assets/js/datatables/jQuery-1.11.3/jquery-1.11.3.js b/web-gui/buildyourownbotnet/assets/js/datatables/jQuery-1.11.3/jquery-1.11.3.js index 6feb11086..89cd81db0 100755 --- a/web-gui/buildyourownbotnet/assets/js/datatables/jQuery-1.11.3/jquery-1.11.3.js +++ b/web-gui/buildyourownbotnet/assets/js/datatables/jQuery-1.11.3/jquery-1.11.3.js @@ -8805,6 +8805,11 @@ function ajaxConvert( s, response, jqXHR, isSuccess ) { // Convert response if prev dataType is non-auto and differs from current } else if ( prev !== "*" && prev !== current ) { + // Mitigate possible XSS vulnerability (gh-2432) + if ( s.crossDomain && current === "script" ) { + continue; + } + // Seek a direct converter conv = converters[ prev + " " + current ] || converters[ "* " + current ];