cbcvebase.
CVE-2016-7103
published 2017-03-15

CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianjqueryui< jqueryui 1.12.1+dfsg-1 (bookworm)jqueryui 1.12.1+dfsg-1 (bookworm)
drupaldrupal_core
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
jqueryjquery-ui>= 0 < 1.12.01.12.0
jqueryuijquery_ui1.10.0 – 1.11.4
juniperjunos
oracleapplication_express< 19.119.1
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclehospitality_cruise_fleet_management
oracleoss_support_tools< 2.12.422.12.42
oracleoss_support_tools
oracleprimavera_unifier16.0 – 16.2
oracleprimavera_unifier17.0 – 17.12.4
oracleprimavera_unifier18.0 – 18.8.4
oraclesiebel_ui_framework<= 21.2
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
redhatopenstack
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM