CVE-2021-41184

⚪ Do wiadomości

Wykonanie nieautoryzowanego kodu w jQuery UI przez niebezpieczne źródła opcji `of`.

CVSS
6.5
EPSS
40.8%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)40.8%
Opublikowano (NVD)2021-10-26 15:15:10 UTC
Ostatnia modyfikacja (NVD)2026-08-25 16:28:27 UTC
Referencje