---
cve: "CVE-2016-7103"
severity: "LOW"
cvss: 3.1
epss: "22.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-03-15 16:59:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T03:19:49+02:00"
---

# CVE-2016-7103

> 3.1 LOW · 🧪 PoC

## Beschreibung

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

## Patch verfügbar (OSV)

- 9644e7bae9116edaf8d37c5b38cb32b892f10ff6 (Commit)

## Referenzen

- <http://rhn.redhat.com/errata/RHSA-2017-0161.html>
- <http://rhn.redhat.com/errata/RHSA-2016-2933.html>
- <http://rhn.redhat.com/errata/RHSA-2016-2932.html>
- <http://www.securityfocus.com/bid/104823>
- <https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2I4UHPIW26FIALH7GGZ3IYUUA53VOOJ/>
- <https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E>
- <https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E>
- <https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E>
- <https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E>
- <https://www.oracle.com/security-alerts/cpuapr2020.html>
- <http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html>
- <https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html>
- <https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html>
- <https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-7103) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
