CVE-2021-41182

⚪ Do wiadomości

Wykorzystanie opcji altField w jQuery-UI przed 1.13.0 może prowadzić do wykonania nieautoryzowanego kodu.

CVSS
6.5
EPSS
39.4%
Exploit
poc
Vendor
oracle
Opis źródłowy (NVD)

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)39.4%
Opublikowano (NVD)2021-10-26 15:15:10 UTC
Ostatnia modyfikacja (NVD)2026-08-25 16:28:27 UTC
Referencje