Executive brief
jQuery MiniColors is a color-picker widget used in web applications. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts through crafted color names, potentially compromising user sessions, stealing credentials, or redirecting users to malicious sites.
Technical details
The vulnerability is a stored/reflected cross-site scripting (CWE-79) flaw in jQuery MiniColors versions prior to 2.3.6. The root cause is improper handling of untrusted color names when constructing DOM elements; specifically, the `title` attribute of swatch color elements was populated directly with user input without sanitization. An attacker can craft a malicious color name containing JavaScript payloads that execute in the context of the victim's browser when the color picker renders. The attack requires network access and user interaction (rendering the color picker with the malicious input). The fix isolates the title attribute assignment using jQuery's `.attr()` method, which performs proper escaping. A patch is available in version 2.3.6 and later.
Affected products
- claviska jquery-minicolors before 2.3.6
Timeline
- 2023-02-21: disclosed: Advisory GHSA-crh5-vv2v-c82q published
- 2.3.6: patched: Fixed in version 2.3.6