jQuery UI – CVE-2021-41184


Kayran has detected that the version of jQuery UI being used is vulnerable to cross-site scripting.
This is caused by accepting the value of the ” of” option of the “.position()” utility.

Accepting the value of the ” of” option of the “.position()” utility from any untrusted sources could lead to untrusted code being executed. Also known as CVE-2021-41184.
An attacker could abuse this to insert and execute commands for his own purposes.


CVSS Version 3.x – 6.1 Medium


To fix CVE-2021-41184, update the jQuery UI version being used to 1.13.0 or higher.
As of now, any string value passed to the of option is now being treated as a CSS selector.

Another option is to not accept the value of the ” of” option from any untrusted sources.




