VulnerabilityModified
CVE-2016-7103
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
MEDIUM 6.1EPSS 22.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 22.58% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jqueryui/jquery ui · oracle/application express · oracle/business intelligence · oracle/hospitality cruise fleet management · oracle/oss support tools · oracle/primavera unifier · oracle/siebel ui framework · oracle/weblogic server · fedoraproject/fedora · netapp/snapcenter · redhat/openstack · juniper/junos · debian/debian linux
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2016-2932.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2933.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0161.htmlThird Party Advisory, VDB Entry
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/104823Broken Link, Third Party Advisory, VDB Entry
- https://github.com/jquery/api.jqueryui.com/issues/281Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/jquery/jquery-ui/commit/9644e7bae9116edaf8d37c5b38cb32b892f10ff6Patch, Third Party Advisory
- https://jqueryui.com/changelog/1.12.0/Release Notes, Vendor Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3EMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2I4UHPIW26FIALH7GGZ3IYUUA53VOOJ/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/Mailing List, Third Party Advisory
- https://nodesecurity.io/advisories/127Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190416-0007/Third Party Advisory
- https://www.drupal.org/sa-core-2022-002Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
- https://www.tenable.com/security/tns-2016-19Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2932.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2933.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.