QID 730263

QID 730263: jQueryUI Cross-Site Scripting Vulnerability

jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.

Affected Versions:
jQuery versions greater prior to version 1.13.0.

QID Detection Logic(Unauthenticated):
It checks for vulnerable versions of jQuery UI from default web page.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    N/A

    CVEs related to QID 730263

    Software Advisories
    Advisory ID Software Component Link
    jquery ui URL Logo blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released