jQuery-ui-dialog - XSS vulnerability under 1.10.0, title attribute

Impact area

Security

Severity

High

Affected element

ServiceNow

UI Script

Salesforce

Static Resource


Rule number

SN-JSL-015 (for ServiceNow)

SF-JSL-015 (for Salesforce)

Impact

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

Remediation

Update jQuery to the latest version.

Time to fix

30 min




Last modified on Aug 19, 2020