CVE-2021-41183 is a medium-severity cross-site scripting (XSS) vulnerability in jQuery UI's Datepicker widget, affecting versions prior to 1.13.0. It allows untrusted code execution if the *Text options of the Datepicker widget accept values from untrusted sources, impacting products like Debian, Drupal, and Oracle. The vulnerability has a CVSS score of 6.1, indicating a network-based attack requiring user interaction, with potential for low impact on confidentiality and integrity. While there is no evidence of active exploitation, no public exploit code, and it is not on CISA's KEV catalog, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.0CPE matchmatch criteria | cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:jquery:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Certain HP Enterprise LaserJet, LaserJet Managed printers - Potential denial of service, potential Cross Site Scripting (XSS)
Oct 4, 2023August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023XSS in `*Text` options of the Datepicker widget in jquery-ui
Oct 26, 2021jquery-ui: XSS in *Text options of the datepicker widget
Oct 25, 2021