Unknown
CVE-2021-41184
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-41184
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of
option of the .position()
util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of
option is now treated as a CSS selector. A workaround is to not accept the value of the of
option from untrusted sources.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- drupal,
- fedoraproject,
- jqueryui,
- netapp,
- oracle,
- tenable
Products
- agile plm 9.3.6,
- application express,
- banking platform 2.12.0,
- banking platform 2.9.0,
- big data spatial and graph,
- big data spatial and graph 23.1,
- communications interactive session recorder 6.4,
- communications operations monitor 4.3,
- communications operations monitor 4.4,
- communications operations monitor 5.0,
- drupal,
- fedora 33,
- fedora 34,
- fedora 35,
- fedora 36,
- h300e firmware -,
- h300s firmware -,
- h410c firmware -,
- h410s firmware -,
- h500e firmware -,
- h500s firmware -,
- h700e firmware -,
- h700s firmware -,
- hospitality inventory management 9.1.0,
- hospitality materials control 18.1,
- hospitality suite8,
- hospitality suite8 8.10.2,
- jd edwards enterpriseone tools,
- jquery ui,
- peoplesoft enterprise peopletools 8.58,
- peoplesoft enterprise peopletools 8.59,
- policy automation,
- primavera unifier,
- primavera unifier 18.8,
- primavera unifier 19.12,
- primavera unifier 20.12,
- primavera unifier 21.12,
- rest data services,
- rest data services 22.1.1,
- tenable.sc,
- weblogic server 12.2.1.3.0,
- weblogic server 12.2.1.4.0,
- weblogic server 14.1.1.0.0
References
Advisory
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: