gvas / knockout-jqueryui

Knockout bindings for the jQuery UI widgets.
http://gvas.github.com/knockout-jqueryui/
MIT License
103 stars 38 forks source link

knockout-jqueryui 2.2.2 (XSS Vulnerability) #76

Open Inscramble opened 1 year ago

Inscramble commented 1 year ago

Hi

I have found a security vulnerability on knockout-jqueryui v2.2.2 for cross site scripting in the Sonatype analysis. CVE-2010-5312: Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. Please solve this issue as soon as possible. This issue is also there in the latest versions of it.