← All CVEs

CVE-2021-41184

medium · 6.5

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

6.5
CVSS
40.8%
EPSS (exploit prob.)
99th
EPSS percentile
2021-10-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
jqueryuijquery_ui< 1.13.0
fedoraprojectfedora33
fedoraprojectfedora34
fedoraprojectfedora35
fedoraprojectfedora36
netapph300s_firmwareall versions
netapph300sall versions
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph300e_firmwareall versions
netapph300eall versions
netapph500e_firmwareall versions
netapph500eall versions
netapph700e_firmwareall versions
netapph700eall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph410c_firmwareall versions
netapph410call versions
drupaldrupal>= 7.0, < 7.86
drupaldrupal>= 9.2.0, < 9.2.11
drupaldrupal>= 9.3.0, < 9.3.3
tenabletenable.sc< 5.21.0
oracleagile_product_lifecycle_management9.3.6
oracleapplication_express< 22.1.1
oraclebanking_platform2.9.0
oraclebanking_platform2.12.0
oraclebig_data_spatial_and_graph< 23.1
oraclebig_data_spatial_and_graph23.1
oraclecommunications_interactive_session_recorder6.4
oraclecommunications_operations_monitor4.3
oraclecommunications_operations_monitor4.4
oraclecommunications_operations_monitor5.0
oraclehospitality_inventory_management9.1.0
oraclehospitality_materials_control18.1
oraclehospitality_suite8>= 8.11.0, <= 8.14.0
oraclehospitality_suite88.10.2
oraclejd_edwards_enterpriseone_tools<= 9.2.6.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-41184