CVE-2016-7103

Description

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
1.397

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 10.3.6.0.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.1.3.0.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3.0Windows
Multiple Vulnerabilities are affected in Netapp Snapcenter -Windows
Vulnerabilities CVE-2016-7103 are fixed in WebJars - jquery-ui 1.12.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Vulnerabilities CVE-2016-7103 are fixed in Ruby-jquery-ui-rails 6.0.0Windows
Vulnerabilities CVE-2016-7103 are fixed in Nuget - jQuery.UI.Combined 1.12.0Windows
JavaScript UI library for dynamic web applications (USN-6419-1) node-jquery-ui_1.12.1+dfsg-5ubuntu0.20.04.1_all.debLinux
JavaScript UI library for dynamic web applications (USN-6419-1) node-jquery-ui_1.12.1+dfsg-5_all.debLinux
JavaScript UI library for dynamic web applications (USN-6419-1) libjs-jquery-ui_1.12.1+dfsg-5ubuntu0.20.04.1_all.debLinux
JavaScript UI library for dynamic web applications (USN-6419-1) libjs-jquery-ui_1.10.1+dfsg-1_all.debLinux
JavaScript UI library for dynamic web applications (USN-6419-1) libjs-jquery-ui_1.12.1+dfsg-5_all.debLinux
Vulnerabilities CVE-2016-7103 are fixed in WebJars - jquery-ui for Linux 1.12.0Linux
Vulnerabilities CVE-2016-7103 are fixed in Ruby-jquery-ui-rails for Linux 6.0.0Linux
Vulnerabilities CVE-2016-7103 are fixed in Nuget - jQuery.UI.Combined for Linux 1.12.0Linux
Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability (CVE-2016-7103)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234