Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade drupal7 | Aug 22, 2024 | Mar 15, 2017 |
| Debian | — | Upgrade jqueryui | Jan 21, 2022 | Mar 15, 2017 |
| Drupal | — | Upgrade to drupal version 7.86 | Mar 23, 2022 | Mar 15, 2017 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 18, 2026 | Jun 18, 2026 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 29633448 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 29814665 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 29633432 for version 10.3.6.0.0. | Aug 1, 2019 | Mar 15, 2017 |
| Ubuntu | — | Upgrade libjs-jquery-uiUpgrade libjs-jquery-ui (Ubuntu Pro)Upgrade node-jquery-ui (Ubuntu Pro)Upgrade node-jquery-ui | Oct 6, 2023 | Mar 15, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub