CVE-2025-3573

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
Configurations

No configuration.

History

15 Apr 2025, 15:16

Type Values Removed Values Added
Summary
  • (es) Las versiones del paquete jquery-validation anteriores a la 1.20.0 son vulnerables a ataques de cross site scripting (XSS) en la función showLabel(), que puede tomar la entrada de un valor de marcador de posición controlado por el usuario. Este valor rellenará un mensaje mediante $.validator.messages en un diccionario localizable por el usuario.

15 Apr 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 05:15

Updated : 2025-04-15 18:39


NVD link : CVE-2025-3573

Mitre link : CVE-2025-3573

CVE.ORG link : CVE-2025-3573


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')