Reflected cross-site scripting (XSS) In jquery.ui.combined
Description
jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
Affected versions of jquery-ui are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the closeText parameter in the dialog function.
jQuery-UI is a library for manipulating UI elements via jQuery.
Version 1.11.4 has a cross site scripting (XSS) vulnerability in the closeText parameter of the dialog function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector.
Recommendation
Upgrade to jQuery-UI 1.12.0 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 1.12.0 | ||
debian 12 | 1.12.1+dfsg-1 | ||
debian 13 | 1.12.1+dfsg-1 | ||
maven | 1.12.0 | ||
npm | 1.12.0 | ||
debian 11 | 1.12.1+dfsg-1 | ||
debian 14 | 1.12.1+dfsg-1 | ||
rubygems | 6.0.0 |
Aliases
References