cbcvebase.
CVE-2016-7103
published 2017-03-15

CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText…

PriorityP337medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
22.58%
97.5th percentile
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianjqueryui< jqueryui 1.12.1+dfsg-1 (bookworm)jqueryui 1.12.1+dfsg-1 (bookworm)
drupaldrupal_core
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
jqueryjquery-ui>= 0 < 1.12.01.12.0
jqueryuijquery_ui1.10.0 – 1.11.4
juniperjunos
oracleapplication_express< 19.119.1
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclehospitality_cruise_fleet_management
oracleoss_support_tools< 2.12.422.12.42
oracleoss_support_tools
oracleprimavera_unifier16.0 – 16.2
oracleprimavera_unifier17.0 – 17.12.4
oracleprimavera_unifier18.0 – 18.8.4
oraclesiebel_ui_framework<= 21.2
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
redhatopenstack
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.