First published: Wed Mar 15 2017(Updated: )
Affected versions of `jquery-ui` are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the `closeText` parameter in the `dialog` function. jQuery-UI is a library for manipulating UI elements via jQuery. Version 1.11.4 has a cross site scripting (XSS) vulnerability in the `closeText` parameter of the `dialog` function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector. ## Recommendation Upgrade to jQuery-UI 1.12.0 or later.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/jQuery.UI.Combined | <1.12.0 | 1.12.0 |
maven/org.webjars.npm:jquery-ui | <1.12.0 | 1.12.0 |
rubygems/jquery-ui-rails | <6.0.0 | 6.0.0 |
npm/jquery-ui | <1.12.0 | 1.12.0 |
debian/jqueryui | 1.12.1+dfsg-8+deb11u2 1.13.2+dfsg-1 | |
jQuery UI | >=1.10.0<=1.11.4 | |
Oracle Application Express | <19.1 | |
Oracle Business Intelligence Enterprise Edition | =12.2.1.3.0 | |
Oracle Business Intelligence Enterprise Edition | =12.2.1.4.0 | |
Oracle Hospitality Cruise Fleet Management | =9.0.11 | |
Oracle OSS Support Tools | <2.12.42 | |
Oracle OSS Support Tools | =2.12.42 | |
Oracle Primavera Unifier | >=16.0<=16.2 | |
Oracle Primavera Unifier | >=17.0<=17.12.4 | |
Oracle Primavera Unifier | >=18.0<=18.8.4 | |
Oracle Siebel User Interface Framework | <=21.2 | |
Oracle WebLogic Server | =10.3.6.0.0 | |
Oracle WebLogic Server | =12.1.3.0.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Fedora | =30 | |
Fedora | =35 | |
Fedora | =36 | |
NetApp SnapCenter | ||
redhat openstack | =7.0 | |
redhat openstack | =8 | |
redhat openstack | =9 | |
Juniper JUNOS | =21.2 | |
Debian | =9.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query on Cloud Pak for Data | <=2.2 | |
IBM Watson Query on Cloud Pak for Data | <=2.1 | |
IBM Watson Query on Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7103 is a cross-site scripting (XSS) vulnerability in jQuery UI before version 1.12.0.
CVE-2016-7103 allows remote attackers to execute malicious scripts on a victim's browser if arbitrary user input is supplied as the value of the `closeText` parameter in the `dialog` function.
CVE-2016-7103 has a severity value of 6.1 (Medium).
Versions of jQuery UI before 1.12.0 are vulnerable to CVE-2016-7103.
To fix CVE-2016-7103, update jQuery UI to version 1.12.0 or later.