CVE-2021-41184 is a medium-severity cross-site scripting (XSS) vulnerability in jQuery UI versions prior to 1.13.0, affecting products like Drupal, Oracle, and Tenable. This flaw allows untrusted code execution if the 'of' option in the .position() utility accepts unvalidated input. With a CVSS score of 6.1, it requires user interaction and can lead to limited confidentiality and integrity impacts. While no public exploits or Metasploit modules exist, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.0CPE matchmatch criteria | cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:jquery:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Certain HP Enterprise LaserJet, LaserJet Managed printers - Potential denial of service, potential Cross Site Scripting (XSS)
Oct 4, 2023August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023XSS in the `of` option of the `.position()` util in jquery-ui
Oct 26, 2021jquery-ui: XSS in the 'of' option of the .position() util
Oct 25, 2021