CVE-2016-7103
MEDIUMJqueryui Jquery UI < 1.11.4 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
References (28)
... and 8 more
Scores
CVSS v3
6.1
EPSS
0.0140
EPSS Percentile
80.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (26)
jqueryui/jquery_ui
< 1.11.4
oracle/application_express
< 19.1
oracle/business_intelligence
oracle/business_intelligence
oracle/hospitality_cruise_fleet_management
oracle/oss_support_tools
< 2.12.42
oracle/oss_support_tools
oracle/primavera_unifier
< 16.2
oracle/siebel_ui_framework
< 21.2
oracle/weblogic_server
oracle/weblogic_server
oracle/weblogic_server
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
... and 11 more
Timeline
Published
Mar 15, 2017
Tracked Since
Feb 18, 2026