← All CVEs

CVE-2021-41182

medium · 6.5

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

6.5
CVSS
39.4%
EPSS (exploit prob.)
99th
EPSS percentile
2021-10-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
jqueryuijquery_ui< 1.13.0
fedoraprojectfedora33
fedoraprojectfedora34
fedoraprojectfedora35
fedoraprojectfedora36
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph300e_firmwareall versions
netapph300eall versions
netapph500e_firmwareall versions
netapph500eall versions
netapph700e_firmwareall versions
netapph700eall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph410c_firmwareall versions
netapph410call versions
netapph300s_firmwareall versions
netapph300sall versions
debiandebian_linux9.0
drupaldrupal>= 7.0, < 7.86
oraclecommunications_interactive_session_recorder6.4
oraclecommunications_operations_monitor4.3
oraclecommunications_operations_monitor4.4
oraclecommunications_operations_monitor5.0
oraclehospitality_suite8>= 8.11.0, <= 8.14.0
oraclehospitality_suite88.10.2
oraclemysql_enterprise_monitor<= 8.0.29
oracleprimavera_unifier17.7
oracleprimavera_unifier17.8
oracleprimavera_unifier17.9
oracleprimavera_unifier17.10
oracleprimavera_unifier17.11
oracleprimavera_unifier17.12
oracleprimavera_unifier18.8
oracleprimavera_unifier19.12
oracleprimavera_unifier20.12
oracleprimavera_unifier21.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-41182