XSS Vulnerability on closeText option of Dialog jQuery UI
Published: August 27, 2016
SECURITY IDENTIFIERS
- CVE: CVE-2016-7103 (NVD)
- GHSA: GHSA-hpcf-8vf9-q4gj
- Vendor Advisory: https://github.com/jquery/api.jqueryui.com/issues/281
GEM
FRAMEWORK
SEVERITY
PATCHED VERSIONS
>= 6.0.0
DESCRIPTION
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
