Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2889-1 | drupal7 security update |
EUVD |
EUVD-2017-0253 | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. |
Github GHSA |
GHSA-hpcf-8vf9-q4gj | jQuery-UI vulnerable to Cross-site Scripting in dialog closeText |
Ubuntu USN |
USN-6419-1 | jQuery UI vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:50:47.467Z
Reserved: 2016-08-27T00:00:00
Link: CVE-2016-7103
No data.
Status : Deferred
Published: 2017-03-15T16:59:00.173
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-7103
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN