jQuery-ui-tooltip - XSS vulnerability under 1.10.0, title attribute

Impact area

Security

Severity

High

Affected element

ServiceNow

UI Script

Salesforce

Static Resource


Rule number

SN-JSL-014 (for ServiceNow)

SF-JSL-014 (for Salesforce)

Impact

Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

Remediation

Update jQuery to the latest version.

Time to fix

30 min




Last modified on Aug 19, 2020