RubySec

Providing security resources for the Ruby community

CVE-2010-5312 (jquery-ui-rails): Cross-site Scripting in jquery-ui

ADVISORIES

GEM

jquery-ui-rails

SEVERITY

CVSS v3.x: 6.1 (Medium)

CVSS v2.0: 4.3 (Medium)

PATCHED VERSIONS

  • >= 4.0.0

DESCRIPTION

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

RELATED