CVE-2016-7103

MEDIUM6.1EPSS 1.8%

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Published: 10/24/2017Modified: 3/11/2024
Also known as:GHSA-hpcf-8vf9-q4gjDEBIAN-CVE-2016-7103

Description

Affected versions of `jquery-ui` are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the `closeText` parameter in the `dialog` function. jQuery-UI is a library for manipulating UI elements via jQuery. Version 1.11.4 has a cross site scripting (XSS) vulnerability in the `closeText` parameter of the `dialog` function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector. ## Recommendation Upgrade to jQuery-UI 1.12.0 or later.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (40)