Cross-site scripting in jQuery UI - CVE-2016-7103

 

Cross-site scripting in jQuery UI - CVE-2016-7103

Published: December 10, 2016 / Updated: November 20, 2021


Vulnerability identifier: #VU7277
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-7103
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

Vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability is caused by an input validation error in jQuery UI before 1.12.0. A remote authenticated attacker can trick the victim to follow a specially specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

jQuery UI
Modular Switchgear Monitoring (MSM)
OSS Support Tools
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
IBM Engineering Lifecycle Optimization - Publishing
Drupal
Red Hat OpenStack
Fedora
Ubuntu
Oracle WebLogic Server
Oracle Application Express
Siebel UI Framework
libjs-jquery-ui (Ubuntu package)
node-jquery-ui (Ubuntu package)
python-XStatic-jquery-ui
rubygem-jquery-ui-rails
drupal7

How to mitigate CVE-2016-7103

Update to version 1.12.0

jQuery UI - update to 1.12.0
OSS Support Tools - update to 2.12.42
Drupal - update to 7.86
Oracle Application Express - update to 19.1
libjs-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
node-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
python-XStatic-jquery-ui - addressed in versions 1.12.0.1-1.el7, 1.12.0.1-1.fc24, 1.12.0.1-2.fc26, 1.12.0.1-4.fc25
rubygem-jquery-ui-rails - update to 6.0.1-1.fc30
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
drupal7 - addressed in versions 7.92-1.el7, 7.92-1.fc35, 7.92-1.fc36, 7.92-1.fc37

External References

Related Security Bulletins