CVE-2010-5312

Severity
6.1MEDIUM
EPSS
5.2%
top 10.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 24
Latest updateJan 19

Description

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages8 packages

npmjquery-ui1.7.01.10.0
RubyGemsjquery-ui-rails< 4.0.0
NVDjqueryui/jquery_ui< 1.10.0
NuGetjQuery.UI.Combined1.7.01.10.0
Mavenorg.webjars.npm:jquery-ui1.7.01.10.0

Also affects: Debian Linux 7.0, 9.0, Fedora 35, 36

Patches

🔴Vulnerability Details

4
GHSA
Cross-site Scripting in jquery-ui2017-10-24
OSV
Cross-site Scripting in jquery-ui2017-10-24
CVEList
CVE-2010-5312: Cross-site scripting (XSS) vulnerability in jquery2014-11-24
OSV
CVE-2010-5312: Cross-site scripting (XSS) vulnerability in jquery2014-11-24

📋Vendor Advisories

3
Drupal
Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-0022022-01-19
Red Hat
jquery-ui: XSS vulnerability in jQuery.ui.dialog title option2010-09-03
Debian
CVE-2010-5312: jqueryui - Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog wi...2010

💬Community

68
Bugzilla
CVE-2010-5312 python-werkzeug: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]2014-11-21
Bugzilla
CVE-2010-5312 gallery3: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]2014-11-21
Bugzilla
CVE-2010-5312 couchdb: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]2014-11-21
Bugzilla
CVE-2010-5312 yelp-xsl: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]2014-11-21
Bugzilla
CVE-2010-5312 wordpress: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]2014-11-21
CVE-2010-5312 (MEDIUM CVSS 6.1) | Cross-site scripting (XSS) vulnerab | cvebase.io