VDB

CVE-2007-2379

CVE-2007-2379 PUBLISHED CVSS 5 MEDIUM

The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

EPSS 1.37% · 80.6th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
1.37%
80.6th percentile

Affected Products

VendorProductVersions
jqueryjquery
netappsnapcenter
n/an/a*

Timeline

  • Apr 30, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 1, 2022 CVE Updated
  • Mar 7, 2023 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 21, 2025 EPSS Score
  • Mar 26, 2025 EPSS Score
  • Mar 28, 2025 EPSS Score
  • Apr 5, 2025 EPSS Score
  • Apr 6, 2025 EPSS Score
  • Apr 11, 2025 EPSS Score
  • Apr 13, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›