Description
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
References (19)
Core 19
Core References
Exploit, Vendor Advisory
http://bugs.jqueryui.com/ticket/6016
Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190416-0007/
Third Party Advisory
https://www.drupal.org/sa-core-2022-002
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0442.html
Third Party Advisory vendor-advisory
http://www.debian.org/security/2015/dsa-3249
Mailing List, Third Party Advisory mailing-list
http://seclists.org/oss-sec/2014/q4/616
Broken Link, Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/71106
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-1462.html
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/98696
Mailing List, Third Party Advisory mailing-list
http://seclists.org/oss-sec/2014/q4/613
Broken Link, Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1037035
Mailing List, Third Party Advisory mailing-list
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
Mailing List, Third Party Advisory mailing-list
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
Mailing List, Third Party Advisory mailing-list
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/01/msg00014.html
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
Scores
CVSS v3
6.1
EPSS
0.0593
EPSS Percentile
90.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (12)
apache/drill
1.16.0
debian/debian_linux
7.0
debian/debian_linux
9.0
drupal/drupal
7.0 - 7.86
fedoraproject/fedora
35
fedoraproject/fedora
36
jqueryui/jquery_ui
< 1.10.0
netapp/snapcenter
npm/jquery-ui
1.7.0 - 1.10.0npm
nuget/jQuery.UI.Combined
1.7.0 - 1.10.0NuGet
... and 2 more
Published
Nov 24, 2014
Tracked Since
Feb 18, 2026