Vulnerability Database

296,733

Total vulnerabilities in the database

CVE-2021-41182

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the altField option is now treated as a CSS selector. A workaround is to not accept the value of the altField option from untrusted sources.

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
fedoraproject / fedora 33 33.x
fedoraproject / fedora 34 34.x
fedoraproject / fedora 35 35.x
fedoraproject / fedora 36 36.x
debian / debian_linux 9.0 9.0.x
drupal / drupal 7.0 7.86
oracle / hospitality_suite8 8.10.2 8.10.2.x
oracle / weblogic_server 12.2.1.3.0 12.2.1.3.0.x
oracle / primavera_unifier 17.7 17.7.x
oracle / primavera_unifier 17.8 17.8.x
oracle / primavera_unifier 17.9 17.9.x
oracle / primavera_unifier 17.10 17.10.x
oracle / primavera_unifier 17.11 17.11.x
oracle / primavera_unifier 17.12 17.12.x
oracle / primavera_unifier 18.8 18.8.x
oracle / weblogic_server 12.2.1.4.0 12.2.1.4.0.x
oracle / primavera_unifier 19.12 19.12.x
oracle / weblogic_server 14.1.1.0.0 14.1.1.0.0.x
oracle / primavera_unifier 20.12 20.12.x
oracle / communications_interactive_session_recorder 6.4 6.4.x
oracle / communications_operations_monitor 4.3 4.3.x
oracle / communications_operations_monitor 4.4 4.4.x
oracle / communications_operations_monitor 5.0 5.0.x
oracle / primavera_unifier 21.12 21.12.x
oracle / mysql_enterprise_monitor - 8.0.29.x
oracle / hospitality_suite8 8.11.0 8.14.0.x
tenable / tenable.sc - 5.21.0
oracle / primavera_unifier 17.7 17.12.x
oracle / hospitality_materials_control 18.1 18.1.x
oracle / agile_plm 9.3.6 9.3.6.x
oracle / peoplesoft_enterprise_peopletools 8.58 8.58.x
oracle / banking_platform 2.9.0 2.9.0.x
oracle / hospitality_inventory_management 9.1.0 9.1.0.x
oracle / peoplesoft_enterprise_peopletools 8.59 8.59.x
oracle / banking_platform 2.12.0 2.12.0.x
oracle / big_data_spatial_and_graph 23.1 23.1.x
oracle / big_data_spatial_and_graph - 23.1
oracle / jd_edwards_enterpriseone_tools - 9.2.6.3.x
oracle / rest_data_services - 22.1.1
oracle / application_express - 22.1.1
oracle / rest_data_services 22.1.1 22.1.1.x
oracle / policy_automation 12.2.0 12.2.25.x
Node.js icon jquery-ui - 1.13.0
jqueryui / jquery_ui - 1.13.0