{"id":"GHSA-jmh9-6rjq-gjh9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jmh9-6rjq-gjh9","summary":"Vulnerable embedded jQuery Version","details":"### Summary\nPIMCore uses the JavaScript library jQuery in version 3.4.1. This version is vulnerable to cross-site-scripting (XSS).\n\n### Details\nIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.\n\nPublish Date: 2020-04-29\n\nURL:= https://security.snyk.io/package/npm/jquery/3.4.1\n","published":"2024-06-05T13:28:36Z","modified":"2024-12-02T05:44:54.860243Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/admin-ui-classic-bundle","fixedVersion":"1.4.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-jmh9-6rjq-gjh9"},{"type":"PACKAGE","url":"https://github.com/pimcore/admin-ui-classic-bundle"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:44:54.860243Z"}}