Commit 2d698f0ba030aacf5d1a56ee9f6e6f0675c88389
Committed by
Rodrigo Souto
1 parent
6e9b3b36
Exists in
master
and in
29 other branches
Fix jquery xss issue
Showing
1 changed file
with
2 additions
and
1 deletions
Show diff stats
public/javascripts/jquery-latest.js
... | ... | @@ -36,7 +36,8 @@ var jQuery = function( selector, context ) { |
36 | 36 | |
37 | 37 | // A simple way to check for HTML strings or ID strings |
38 | 38 | // (both of which we optimize for) |
39 | - quickExpr = /^(?:[^<]*(<[\w\W]+>)[^>]*$|#([\w\-]+)$)/, | |
39 | + //fix xss: http://ma.la/jquery_xss/ http://blog.jquery.com/2011/09/01/jquery-1-6-3-released/ | |
40 | + quickExpr = /^(?:[^#<]*(<[\w\W]+>)[^>]*$|#([\w\-]*)$)/, | |
40 | 41 | |
41 | 42 | // Check if a string has a non-whitespace character in it |
42 | 43 | rnotwhite = /\S/, | ... | ... |