Executive brief
jQuery UI is a popular JavaScript widget library used to build interactive web components. The Dialog widget—a common tool for displaying messages and forms—fails to safely sanitize the title option, allowing an attacker to inject malicious JavaScript that runs in the context of a user's browser. This could lead to session hijacking, credential theft, or defacement of web applications using affected versions.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in the Dialog widget's title-setting functionality (jquery.ui.dialog.js). The vulnerable component uses .html() or similar unsafe DOM methods to render the title option without proper escaping, allowing an attacker to inject arbitrary HTML and JavaScript. The attack requires user interaction (clicking a link or visiting a malicious page) but requires no authentication. An attacker can craft a malicious URL or web page that opens a Dialog with script-containing title text, resulting in arbitrary JavaScript execution in the victim's browser with access to cookies, session tokens, and page content. The vulnerability was fixed in version 1.10.0 by using .text() instead of unsafe HTML insertion methods to set the dialog title.
Affected products
- jQuery Foundation jQuery UI 1.7.0 to 1.9.x (fixed in 1.10.0)
Timeline
- 2014-11-24: disclosed: NVD publication date
- 2012: patched: Fixed in jQuery UI 1.10.0
- 2017-10-24: advisory: GitHub Security Advisory published