Miggo Logo

CVE-2021-41184:
XSS in the `of` option of the `.position()` util in jquery-ui

6.5

CVSS Score
3.1

Basic Information

EPSS Score
0.96232%
Published
10/26/2021
Updated
10/5/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
jquery-uinpm< 1.13.01.13.0
org.webjars.npm:jquery-uimaven< 1.13.01.13.0
jQuery.UI.Combinednuget< 1.13.01.13.0
jquery-ui-railsrubygems< 7.0.07.0.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t ****ptin* t** v*lu* o* t** `o*` option o* t** [`.position()`](*ttps://*pi.jqu*ryui.*om/position/) util *rom untrust** sour**s m*y *x**ut* untrust** *o**. *or *x*mpl*, invokin* t** *ollowin* *o**: ```js $( "#*l*m*nt" ).position( { my: "l**

Reasoning

No *n*lysis *v*il**l*