CVE-2021-41183Medium· 6.5▾ SunlitjQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 1.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.5%
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various *Text options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various *Text options are now always treated as pure text, not HTML. A workaround is to not accept the value of the *Text options from untrusted sources.
jquery_ui < 1.13.0fedora = 33fedora = 34fedora = 35fedora = 36h300s_firmwareh500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwareh410c_firmwaredebian_linux = 9.0drupal >= 7.0, < 7.86drupal >= 9.2.0, < 9.2.11drupal >= 9.3.0, < 9.3.3agile_product_lifecycle_management = 9.3.6application_express < 22.1.1banking_platform = 2.9.0banking_platform = 2.12.0big_data_spatial_and_graph < 23.1big_data_spatial_and_graph = 23.1communications_interactive_session_recorder = 6.4communications_operations_monitor = 4.3communications_operations_monitor = 4.4communications_operations_monitor = 5.0hospitality_inventory_management = 9.1.0hospitality_suite8 >= 8.11.0, <= 11.14.0hospitality_suite8 = 8.10.2jd_edwards_enterpriseone_tools <= 9.2.6.3mysql_enterprise_monitor <= 8.0.29peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59policy_automation >= 12.2.0, <= 12.2.5primavera_gateway >= 17.7, <= 17.12primavera_gateway = 18.8.0primavera_gateway = 19.12.0primavera_gateway = 20.12.0primavera_gateway = 21.12.0rest_data_services < 22.1.1rest_data_services = 22.1.1weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0tenable.sc < 5.21.0Upgrade past the affected range:
jquery_ui 1.13.0drupal 9.3.3application_express 22.1.1big_data_spatial_and_graph 23.1rest_data_services 22.1.1tenable.sc 5.21.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41182Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2019-1973Medium· 4.8A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface
CVE-2019-10219Medium· 6.1A vulnerability was found in Hibernate-Validator
CVE-2020-1106Medium· 6.1A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server