CVE-2016-7103

MEDIUM6.1EPSS 1.8%

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Published: 10/24/2017Modified: 4/28/2026

Description

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (40)