Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2889-1 | drupal7 security update |
![]() |
EUVD-2017-0253 | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. |
![]() |
GHSA-hpcf-8vf9-q4gj | jQuery-UI vulnerable to Cross-site Scripting in dialog closeText |
![]() |
USN-6419-1 | jQuery UI vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:50:47.467Z
Reserved: 2016-08-27T00:00:00
Link: CVE-2016-7103

No data.

Status : Deferred
Published: 2017-03-15T16:59:00.173
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-7103


No data.