Description
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2007-2115 Vulnerability (CVE-2007-2115)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3378)
MySQL CVE-2018-2786 Vulnerability (CVE-2018-2786)
WordPress 3.8.x Prototype Pollution (3.8 - 3.8.37)
WordPress Plugin Media File Manager Advanced Multiple Vulnerabilities (1.1.5)