Unknown
CVE-2021-41182
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-41182
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField
option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the altField
option is now treated as a CSS selector. A workaround is to not accept the value of the altField
option from untrusted sources.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- debian,
- drupal,
- fedoraproject,
- jqueryui,
- netapp,
- oracle,
- tenable
Products
- agile plm 9.3.6,
- application express,
- banking platform 2.12.0,
- banking platform 2.9.0,
- big data spatial and graph,
- big data spatial and graph 23.1,
- communications interactive session recorder 6.4,
- communications operations monitor 4.3,
- communications operations monitor 4.4,
- communications operations monitor 5.0,
- debian linux 9.0,
- drupal,
- fedora 33,
- fedora 34,
- fedora 35,
- fedora 36,
- h300e firmware -,
- h300s firmware -,
- h410c firmware -,
- h410s firmware -,
- h500e firmware -,
- h500s firmware -,
- h700e firmware -,
- h700s firmware -,
- hospitality inventory management 9.1.0,
- hospitality materials control 18.1,
- hospitality suite8,
- hospitality suite8 8.10.2,
- jd edwards enterpriseone tools,
- jquery ui,
- mysql enterprise monitor,
- peoplesoft enterprise peopletools 8.58,
- peoplesoft enterprise peopletools 8.59,
- policy automation,
- primavera unifier,
- primavera unifier 17.10,
- primavera unifier 17.11,
- primavera unifier 17.12,
- primavera unifier 17.7,
- primavera unifier 17.8,
- primavera unifier 17.9,
- primavera unifier 18.8,
- primavera unifier 19.12,
- primavera unifier 20.12,
- primavera unifier 21.12,
- rest data services,
- rest data services 22.1.1,
- tenable.sc,
- weblogic server 12.2.1.3.0,
- weblogic server 12.2.1.4.0,
- weblogic server 14.1.1.0.0
References
Advisory
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: