QID 980932

QID 980932: Nodejs (npm) Security Update for jquery-ui (GHSA-qqxp-xp9v-vvx6)

Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-qqxp-xp9v-vvx6 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980932

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qqxp-xp9v-vvx6 jquery-ui URL Logo github.com/advisories/GHSA-qqxp-xp9v-vvx6