CVE-2016-7103
ADVISORY - githubSummary
Affected versions of jquery-ui
are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the closeText
parameter in the dialog
function.
jQuery-UI is a library for manipulating UI elements via jQuery.
Version 1.11.4 has a cross site scripting (XSS) vulnerability in the closeText
parameter of the dialog
function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector.
Recommendation
Upgrade to jQuery-UI 1.12.0 or later.
Common Weakness Enumeration (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
NIST
2.8
CVSS SCORE
6.1mediumGitHub
2.8
CVSS SCORE
6.1mediumAlpine
-
Debian
-
Ubuntu
2.8
CVSS SCORE
6.1mediumRed Hat
2.8
CVSS SCORE
6.1lowintheWild
-
-