aboutsummaryrefslogtreecommitdiffstats
path: root/phpBB/assets/javascript/core.js
diff options
context:
space:
mode:
authorMarc Alexander <admin@m-a-styles.de>2018-12-19 19:59:19 +0100
committerMarc Alexander <admin@m-a-styles.de>2018-12-19 19:59:19 +0100
commit85ecd2c7bea9eec65e1f0be8b736de22df249c79 (patch)
tree55cc4487d37e11cede1ec95a7047d962837b330b /phpBB/assets/javascript/core.js
parent2a72b9b3ecf47947ddaf32564ec5810f37dd621a (diff)
parent37b33e6b6772d5ed6ad6e538754a2a82b37441b1 (diff)
downloadforums-85ecd2c7bea9eec65e1f0be8b736de22df249c79.tar
forums-85ecd2c7bea9eec65e1f0be8b736de22df249c79.tar.gz
forums-85ecd2c7bea9eec65e1f0be8b736de22df249c79.tar.bz2
forums-85ecd2c7bea9eec65e1f0be8b736de22df249c79.tar.xz
forums-85ecd2c7bea9eec65e1f0be8b736de22df249c79.zip
Merge pull request #43 from phpbb/security/229
[security/229] Update jQuery to 1.12.4
Diffstat (limited to 'phpBB/assets/javascript/core.js')
-rw-r--r--phpBB/assets/javascript/core.js7
1 files changed, 7 insertions, 0 deletions
diff --git a/phpBB/assets/javascript/core.js b/phpBB/assets/javascript/core.js
index 02d7323dfb..5218a8c1be 100644
--- a/phpBB/assets/javascript/core.js
+++ b/phpBB/assets/javascript/core.js
@@ -20,6 +20,13 @@ var phpbbAlertTimer = null;
phpbb.isTouch = (window && typeof window.ontouchstart !== 'undefined');
+// Add ajax pre-filter to prevent cross-domain script execution
+$.ajaxPrefilter(function(s) {
+ if (s.crossDomain) {
+ s.contents.script = false;
+ }
+});
+
/**
* Display a loading screen
*