Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQuery UI.
History

Fri, 25 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQuery UI.

Sat, 19 Oct 2024 01:30:00 +0000

Type Values Removed Values Added
Title jquery-ui: XSS via window.addEventListener
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Jqueryui
Jqueryui jquery Ui
Weaknesses CWE-79
CPEs cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:*:*:*
Vendors & Products Jqueryui
Jqueryui jquery Ui
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-17T00:00:00

Updated: 2024-10-25T15:44:23.992390

Reserved: 2024-03-27T00:00:00

Link: CVE-2024-30875

cve-icon Vulnrichment

Updated: 2024-10-18T19:15:55.275Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-17T22:15:02.977

Modified: 2024-10-25T16:15:09.693

Link: CVE-2024-30875

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-10-17T00:00:00Z

Links: CVE-2024-30875 - Bugzilla