Vulnerabilities/

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Severity:
Medium

Description

Affected versions of jquery-ui are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the closeText parameter in the dialog function.

jQuery-UI is a library for manipulating UI elements via jQuery.

Version 1.11.

Recommendation

Update the jquery-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jquery-ui
Anything's wrong? Let us know Last updated on September 26, 2023

This issue is available in SmartScanner Professional

See Pricing