CVE-2021-41182 is a cross-site scripting (XSS) vulnerability in jQuery UI's Datepicker widget, affecting versions prior to 1.13.0, including products like Debian, Drupal, and Oracle. It occurs when untrusted input is accepted for the `altField` option, potentially leading to arbitrary code execution. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction and network access, with potential impacts on confidentiality and integrity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.0CPE matchmatch criteria | cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:jquery:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Certain HP Enterprise LaserJet, LaserJet Managed printers - Potential denial of service, potential Cross Site Scripting (XSS)
Oct 4, 2023August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023XSS in the `altField` option of the Datepicker widget in jquery-ui
Oct 26, 2021jquery-ui: XSS in the altField option of the datepicker widget
Oct 25, 2021