CVE-2024-30875
EPSS 0.79%
Description
Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component.
How to fix CVE-2024-30875
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/jqueryui—no fix listed
Is CVE-2024-30875 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0