CVE-2016-7103

Aliases:GHSA-hpcf-8vf9-q4gj
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 15 Mar 2017, 00:00
Last modified:06 Aug 2024, 01:50

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
6.1 MEDIUM
v3.1 (nvd)
EPSS Score
1.78% LOW
2% probability +0.38%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

15 Mar 2017, 00:00
Published
Vulnerability first disclosed
06 Aug 2024, 01:50
Last Modified
Vulnerability information updated

Description

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 1.78% Percentile: 83%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    30 | 35 | 36

  • RubyGemsjquery-ui-rails

    < 6.0.0

  • jqueryuijquery_ui

    ≥ 1.10.0, ≤ 1.11.4

  • juniperjunos

    21.2

  • org.webjars.npmjquery-ui

    < 1.12.0

  • netappsnapcenter

    na

  • Npmjquery-ui

    < 1.12.0

  • NuGetjQuery.UI.Combined

    < 1.12.0

  • oracleapplication_express

    < 19.1

  • oraclebusiness_intelligence

    12.2.1.3.0 | 12.2.1.4.0

  • oraclehospitality_cruise_fleet_management

    9.0.11

  • oracleoss_support_tools

    < 2.12.42 | 2.12.42

  • oracleprimavera_unifier

    ≥ 16.0, ≤ 16.2 | ≥ 17.0, ≤ 17.12.4 | ≥ 18.0, ≤ 18.8.4

  • oraclesiebel_ui_framework

    ≤ 21.2

  • UnknownWebLogic Server

    10.3.6.0.0 | 12.1.3.0.0 | 12.2.1.3.0

  • redhatopenstack

    7.0 | 8 | 9

References (47)