PT-2017-4095 · Jquery+5 · Jquery Ui+5
CVE-2016-7103
·
Publicado
2017-03-15
·
Atualizado
2025-06-17
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
jQuery UI versions prior to 1.12.0
Description
A cross-site scripting (XSS) issue might allow remote attackers to inject arbitrary web script or HTML via the
closeText parameter of the dialog function. This vulnerability is related to the lack of protection measures for the web page structure. If an application passes user input to the closeText parameter, it may be vulnerable to XSS via this attack vector.Recommendations
Upgrade to jQuery-UI 1.12.0 or later. As a temporary workaround, consider restricting the use of the
closeText parameter in the dialog function to minimize the risk of exploitation. Avoid passing arbitrary user input to the closeText parameter until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Junos
Linuxmint
Oracle Weblogic Server
Ubuntu
Jquery Ui