Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 25 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. | Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQuery UI. |
Sat, 19 Oct 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jquery-ui: XSS via window.addEventListener | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 18 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jqueryui
Jqueryui jquery Ui |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jqueryui
Jqueryui jquery Ui |
|
| Metrics |
cvssV3_1
|
Thu, 17 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-25T15:44:23.992390
Reserved: 2024-03-27T00:00:00
Link: CVE-2024-30875
Updated: 2024-10-18T19:15:55.275Z
Status : Awaiting Analysis
Published: 2024-10-17T22:15:02.977
Modified: 2024-10-25T16:15:09.693
Link: CVE-2024-30875
OpenCVE Enrichment
No data.