jQuery UI – CVE-2021-41184

Description

Kayran has detected that the version of jQuery UI being used is vulnerable to cross-site scripting.
This is caused by accepting the value of the ” of” option of the “.position()” utility.

Accepting the value of the ” of” option of the “.position()” utility from any untrusted sources could lead to untrusted code being executed. Also known as CVE-2021-41184.
An attacker could abuse this to insert and execute commands for his own purposes.

Severity/Score

CVSS Version 3.x – 6.1 Medium

Recommendation

To fix CVE-2021-41184, update the jQuery UI version being used to 1.13.0 or higher.
As of now, any string value passed to the of option is now being treated as a CSS selector.

Another option is to not accept the value of the ” of” option from any untrusted sources.

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41184

https://cwe.mitre.org/data/definitions/79.html

< Return to all Vulnerabilities

Explaining API

We’ve talked about API’s Vulnerability in here, but i feel like there’s much more to talk about and explain since this is a big and

Read More »

The Cloud

I’m pretty sure there isn’t a single adult in the world who hasn’t at least heard of The Cloud. Explaining “The Cloud” in 2022 may

Read More »

Red Team

You’ve probably heard that there are teams in the Cyber field called Red Team and Blue Team. Let’s talk about the red one, shall we?

Read More »

Using VPN

What is a VPN? Why should someone be using VPN? Which Problems does is solve? and what is the advantages and disadvantages of it? Let’s

Read More »