CVE-2021-41182Medium· 6.5▾ TwilightPoC availablejQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 7.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
39%
1 GitHub repo
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the altField option is now treated as a CSS selector. A workaround is to not accept the value of the altField option from untrusted sources.
jquery_ui < 1.13.0fedora = 33fedora = 34fedora = 35fedora = 36h500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwareh410c_firmwareh300s_firmwaredebian_linux = 9.0drupal >= 7.0, < 7.86communications_interactive_session_recorder = 6.4communications_operations_monitor = 4.3communications_operations_monitor = 4.4communications_operations_monitor = 5.0hospitality_suite8 >= 8.11.0, <= 8.14.0hospitality_suite8 = 8.10.2mysql_enterprise_monitor <= 8.0.29primavera_unifier = 17.7primavera_unifier = 17.8primavera_unifier = 17.9primavera_unifier = 17.10primavera_unifier = 17.11primavera_unifier = 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12primavera_unifier = 21.12weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0tenable.sc < 5.21.0agile_product_lifecycle_management = 9.3.6application_express < 22.1.1banking_platform = 2.9.0banking_platform = 2.12.0big_data_spatial_and_graph < 23.1big_data_spatial_and_graph = 23.1hospitality_inventory_management = 9.1.0hospitality_materials_control = 18.1jd_edwards_enterpriseone_tools <= 9.2.6.3peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59policy_automation >= 12.2.0, <= 12.2.25primavera_unifier >= 17.7, <= 17.12rest_data_services < 22.1.1rest_data_services = 22.1.1Upgrade past the affected range:
jquery_ui 1.13.0drupal 7.86tenable.sc 5.21.0application_express 22.1.1big_data_spatial_and_graph 23.1rest_data_services 22.1.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41183Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2019-10219Medium· 6.1A vulnerability was found in Hibernate-Validator
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …
CVE-2018-6882Medium· 6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…