← All CVEs

CVE-2010-5312

medium · 6.1

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

6.1
CVSS
18.4%
EPSS (exploit prob.)
97th
EPSS percentile
2014-11-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
debiandebian_linux7.0
jqueryuijquery_ui< 1.10.0
fedoraprojectfedora35
fedoraprojectfedora36
netappsnapcenterall versions
apachedrill1.16.0
drupaldrupal>= 7.0, < 7.86
debiandebian_linux9.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-5312