[buddypress-trac] [BuddyPress Trac] #8790: "Potentially Suspicious" /wp-content/plugins/buddypress/bp-core/js/vendor/jquery-cookie.min.js?ver=10.6.0

buddypress-trac noreply at wordpress.org
Tue Jan 3 19:27:57 UTC 2023


#8790: "Potentially Suspicious" /wp-content/plugins/buddypress/bp-core/js/vendor
/jquery-cookie.min.js?ver=10.6.0
--------------------------+-----------------------------
 Reporter:  boxhamster    |      Owner:  (none)
     Type:  defect (bug)  |     Status:  new
 Priority:  low           |  Milestone:  Awaiting Review
Component:  (not sure)    |    Version:  10.6.0
 Severity:  normal        |   Keywords:
--------------------------+-----------------------------
 Hi,

 I wanted to inform you of the warning I just got on
 https://scanner.pcrisk.com/ in regards to BP. I'm aware this might just be
 a false positive, in that case, please ignore, but thank you for looking
 into this. :)

 /wp-content/plugins/buddypress/bp-core/js/vendor/jquery-
 cookie.min.js?ver=10.6.0
 Severity:
         Potentially Suspicious
 Reason:
         Detected potentially suspicious initialization of function pointer
 to JavaScript method String.replace CcodeE __tmpvar1170183340 =
 String.replace; Ccode/E
 Details:
         Detected potentially suspicious content.
 Offset:
         264
 Threat dump:
         View code (see below)
 File size[byte]:
         1229
 File type:
         ASCII
 MD5:
         AD70A8BA0464EF7223BA502399938847
 Scan duration[sec]:
         0.045

 The following code was shown under "View code":
 [[==e.indexOf('"')%26%26(e=e.slice(1,-1).replace(/\\"/g,'"').replace(/\\\\/g,"\\"));try{return
 e=decodeURIComponent(e.replace(n,"
 ")),x.json?JSON.parse(e):e}catch(e){}}(e);return"function"==typeof
 o?o(e):e}var x=d.cookie=function(e,o,n){var i,t;if(void 0!==o%26%26"f]]

-- 
Ticket URL: <https://buddypress.trac.wordpress.org/ticket/8790>
BuddyPress Trac <http://buddypress.org/>
BuddyPress Trac


More information about the buddypress-trac mailing list