Junglewise Threat Intelligence

CVE-2022-31160: jQuery UI XSS in checkboxradio refresh with HTML-like label text

CVE-2022-31160 · Severity: low · CVSS 3.1 · Published 2022-07-18

Technologies: jquery-ui (npm), jQuery.UI.Combined (NuGet), jquery-ui-rails (RubyGems), org.webjars.npm:jquery-ui (Maven). Vendors: npm, NuGet, RubyGems, jQuery, Maven.

Executive brief

jQuery UI is a popular JavaScript library that provides interactive user interface components for web applications. A vulnerability in its checkboxradio widget allows attackers to execute arbitrary JavaScript code if the widget is refreshed while containing encoded HTML entities in label text. This could enable account takeover, session hijacking, or malware injection in affected web applications.

Technical details

The vulnerability is a stored/reflected cross-site scripting (XSS) flaw in jQuery UI's checkboxradio widget. When a checkboxradio widget is initialized on an input element within a label, and then refreshed via the .checkboxradio("refresh") method, HTML-encoded entities in the label text are improperly decoded and inserted into the DOM without sanitization. This occurs because the widget extracts label contents and processes them through text manipulation that converts HTML entities (e.g., < to <) before rendering. An attacker who can control the initial HTML structure can inject malicious event handlers (e.g., onerror attributes) that execute arbitrary JavaScript when the page loads or the widget refreshes. The attack requires no authentication and only user interaction to load the affected page. The vulnerability has been patched in jQuery UI version 1.13.2 and later.

Affected products

  • jQuery UI before 1.13.2

Timeline

  • 2022-07-15: disclosed: Advisory published
  • 2022-07-18: patched: jQuery UI 1.13.2 released with patch

References

Related threats