CVE-2021-41184

Aliases:GHSA-gpqq-952q-5327BIT-drupal-2021-41184
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 26 Oct 2021, 00:00
Last modified:04 Nov 2025, 16:09

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
31.1% HIGH
31% probability +9.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Oct 2021, 00:00
Published
Vulnerability first disclosed
04 Nov 2025, 16:09
Last Modified
Vulnerability information updated

Description

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 31.10% Percentile: 97%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • drupaldrupal

    ≥ 7.0, < 7.86 | ≥ 9.2.0, < 9.2.11 | ≥ 9.3.0, < 9.3.3

  • fedoraprojectfedora

    33 | 34 | 35 | 36

  • RubyGemsjquery-ui-rails

    < 7.0.0

  • jqueryjquery-ui

    < 1.13.0

  • jqueryuijquery_ui

    < 1.13.0

  • org.webjars.npmjquery-ui

    < 1.13.0

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • Npmjquery-ui

    < 1.13.0

  • NuGetjQuery.UI.Combined

    < 1.13.0

  • oracleagile_plm

    9.3.6

  • oracleapplication_express

    < 22.1.1

  • oraclebanking_platform

    2.9.0 | 2.12.0

  • oraclebig_data_spatial_and_graph

    < 23.1 | 23.1

  • oraclecommunications_interactive_session_recorder

    6.4

  • oraclecommunications_operations_monitor

    4.3 | 4.4 | 5.0

  • oraclehospitality_inventory_management

    9.1.0

  • oraclehospitality_materials_control

    18.1

  • oraclehospitality_suite8

    ≥ 8.11.0, ≤ 8.14.0 | 8.10.2

  • oraclejd_edwards_enterpriseone_tools

    ≤ 9.2.6.3

  • oraclepeoplesoft_enterprise_peopletools

    8.58 | 8.59

  • oraclepolicy_automation

    ≥ 12.2.0, ≤ 12.2.25

  • oracleprimavera_unifier

    ≥ 17.7, ≤ 17.12 | 18.8 | 19.12 | 20.12 | 21.12

  • oraclerest_data_services

    < 22.1.1 | 22.1.1

  • UnknownWebLogic Server

    12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0

  • tenabletenable.sc

    < 5.21.0

References (29)