Back

MEDIUM

jquery-validation: XSS Vulnerability in jquery-validation

Published Apr 15, 2025

Description

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner snyk
Published Apr 15, 2025
Updated Apr 15, 2025
Reserved Apr 14, 2025

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Apr 15, 2025
Bugzilla 2359682

ENISA EUVD

Assigner snyk
Published Apr 15, 2025
Updated Apr 15, 2025