Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
2017-03-15T16:59:00.173
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jqueryui | jquery_ui | ≤ 1.11.4 | Yes |
Application | oracle | application_express | < 19.1 | Yes |
Application | oracle | business_intelligence | 12.2.1.3.0 | Yes |
Application | oracle | business_intelligence | 12.2.1.4.0 | Yes |
Application | oracle | hospitality_cruise_fleet_management | 9.0.11 | Yes |
Application | oracle | oss_support_tools | < 2.12.42 | Yes |
Application | oracle | oss_support_tools | 2.12.42 | Yes |
Application | oracle | primavera_unifier | ≤ 16.2 | Yes |
Application | oracle | primavera_unifier | ≤ 17.12.4 | Yes |
Application | oracle | primavera_unifier | ≤ 18.8.4 | Yes |
Application | oracle | siebel_ui_framework | ≤ 21.2 | Yes |
Application | oracle | weblogic_server | 10.3.6.0.0 | Yes |
Application | oracle | weblogic_server | 12.1.3.0.0 | Yes |
Application | oracle | weblogic_server | 12.2.1.3.0 | Yes |
Operating System | fedoraproject | fedora | 30 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |
Application | netapp | snapcenter | - | Yes |
Application | redhat | openstack | 7.0 | Yes |
Application | redhat | openstack | 8 | Yes |
Application | redhat | openstack | 9 | Yes |
Operating System | juniper | junos | 21.2 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |