Junglewise Threat Intelligence

CVE-2021-41182: jQuery UI Datepicker XSS in altField option

CVE-2021-41182 · Severity: low · CVSS 3.1 · Published 2021-10-26

Technologies: jquery-ui (npm), jQuery.UI.Combined (NuGet), jquery-ui-rails (RubyGems), org.webjars.npm:jquery-ui (Maven). Vendors: npm, NuGet, RubyGems, jQuery, Maven.

Executive brief

jQuery UI is a popular JavaScript library that provides interactive widgets including a date picker component used on many websites. A vulnerability in the altField option allows attackers to execute arbitrary JavaScript code when a date picker is initialized with untrusted input from user-controlled sources. This can enable attackers to steal user credentials, perform actions on behalf of users, or inject malicious content into web pages.

Technical details

This is a cross-site scripting (XSS) vulnerability in jQuery UI's Datepicker widget, specifically in how it handles the altField option parameter. The vulnerable component fails to sanitize or escape HTML content passed to the altField option, allowing attackers to inject arbitrary HTML and JavaScript code. The attack requires user interaction (opening/initializing the datepicker) and network reachability to a vulnerable web page, but does not require authentication. An attacker who can control the altField value—either through URL parameters, form inputs, or other untrusted sources—can execute arbitrary JavaScript in the victim's browser context. The issue is fixed in jQuery UI version 1.13.0, which now treats all string values passed to altField as CSS selectors rather than HTML content.

Affected products

  • jQuery UI before 1.13.0

Timeline

  • 2021-10-26: disclosed
  • 2021-10-26: patched: jQuery UI 1.13.0 released

References

Related threats