CVE-2010-5312 is a cross-site scripting (XSS) vulnerability found in the Dialog widget of jQuery UI before version 1.10.0, specifically within the jquery.ui.dialog.js file, affecting products like Apache, Debian, and Drupal. This medium-severity vulnerability (CVSS 6.1) allows remote attackers to inject arbitrary web script or HTML via the title option, requiring user interaction but with low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, and it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
< 1.10.0CPE matchmatch criteria | cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:jquery:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.