jquery-form/form

Fortify SCA: Code Injection .

Open

#554 创建于 2018年8月3日

在 GitHub 查看
 (7 评论) (0 反应) (0 负责人)JavaScript (5,209 star) (2,199 fork)batch import
help wantedneed more info

描述

Please review Instructions for Reporting a Bug.

Description:

I have no idea about whether it has been fixed in later versions. but the code scan is not passed.

Expected Behavior:

Actual behavior:

Source: jquery.form.js:812 Read xhr.responseXML() 810 var ct = xhr.getResponseHeader('content-type') || '', 811 xml = type === 'xml' || !type && ct.indexOf('xml') >= 0, 812 data = xml ? xhr.responseXML : xhr.responseText; 813 814 if (xml && data.documentElement.nodeName === 'parsererror') { Sink: jquery.form.js:781 setTimeout() 779 780 // clean up 781 setTimeout(function() { 782 if (!s.iframeTarget) { 783 $io.remove();

Versions:

jqform:3.51

贡献者指南