VDB
Sign up
MEDIUM6.1

GHSA-hpcf-8vf9-q4gj

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Quick fix

GHSA-hpcf-8vf9-q4gj — jquery-ui: upgrade to the fixed version with the command below.

npm install jquery-ui@1.12.0

Details

Affected versions of `jquery-ui` are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the `closeText` parameter in the `dialog` function.

jQuery-UI is a library for manipulating UI elements via jQuery.

Version 1.11.4 has a cross site scripting (XSS) vulnerability in the `closeText` parameter of the `dialog` function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector.

## Recommendation

Upgrade to jQuery-UI 1.12.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery-ui
Introduced in: 0Fixed in: 1.12.0
Fixnpm install jquery-ui@1.12.0
RubyGems/jquery-ui-rails
Introduced in: 0Fixed in: 6.0.0
Fixbundle update jquery-ui-rails
Maven/org.webjars.npm:jquery-ui
Introduced in: 0Fixed in: 1.12.0
Fix# pom.xml: bump <version>1.12.0</version> for org.webjars.npm:jquery-ui
NuGet/jQuery.UI.Combined
Introduced in: 0Fixed in: 1.12.0
Fixdotnet add package jQuery.UI.Combined --version 1.12.0

References