On Github willdurand-edu / web-security-101-slides
It is a communication technique used in JavaScript applications to request data from a server in a different domain:
<!-- Request sent via a `script` tag --> <script src="https://example.com/status.json?callback=apiStatus"></script>
<!-- Data received as an execution of the predefined function --> <script>function apiStatus(data) { console.log(data.status); }</script>