vendor:
jQuery UI
by:
Rafael Cintra Lopes
8.8
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: jQuery UI
Affected Version From: <= 1.12.1
Affected Version To: None
Patch Exists: YES
Related CWE: CVE-2020-28488
CPE: jquery:jquery_ui
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2021
jQuery UI 1.12.1 – Denial of Service (DoS)
A denial of service vulnerability exists in jQuery UI version 1.12.1 and prior. An attacker can exploit this vulnerability by creating a dialog box with a long title, which will cause the application to crash. This can be done by using the jQuery UI dialog() method and passing a long string as the title parameter.
Mitigation:
Upgrade to the latest version of jQuery UI.