VDB
Sign up
MEDIUM

GHSA-qqxp-xp9v-vvx6

jquery-ui Tooltip widget vulnerable to XSS

Quick fix

GHSA-qqxp-xp9v-vvx6 — jquery-ui: upgrade to the fixed version with the command below.

npm install jquery-ui@1.10.0

Details

Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery-ui
Introduced in: 0Fixed in: 1.10.0
Fixnpm install jquery-ui@1.10.0
RubyGems/jquery-ui-rails
Introduced in: 0Fixed in: 4.0.0
Fixbundle update jquery-ui-rails
Maven/org.webjars.npm:jquery-ui
Introduced in: 0Fixed in: 1.10.0
Fix# pom.xml: bump <version>1.10.0</version> for org.webjars.npm:jquery-ui
NuGet/jQuery.UI.Combined
Introduced in: 0Fixed in: 1.10.0
Fixdotnet add package jQuery.UI.Combined --version 1.10.0

References