Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
{
"binaries": [
{
"binary_version": "4.7.1+dfsg-2ubuntu1",
"binary_name": "civicrm-common"
},
{
"binary_version": "4.7.1+dfsg-2ubuntu1",
"binary_name": "civicrm-l10n"
},
{
"binary_version": "4.7.1+dfsg-2ubuntu1",
"binary_name": "drupal7-mod-civicrm"
},
{
"binary_version": "4.7.1+dfsg-2ubuntu1",
"binary_name": "wordpress-civicrm"
}
]
}{
"binaries": [
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-blacklist-number"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-external-script"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-jsonrpc"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-phonebook-ldap"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-phonebook-lookup"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-rest-api"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-server-alert"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-simple-autoreply"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-sms-credit"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-sms-member"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-sms-to-email"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-sms-to-twitter"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-sms-to-wordpress"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-sms-to-xmpp"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-soap"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-stop-manager"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-welcome"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-whitelist-number"
},
{
"binary_version": "0.8.3~rc-2-1",
"binary_name": "kalkun-plugin-xmlrpc"
}
]
}{
"binaries": [
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-blacklist-number"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-external-script"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-jsonrpc"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-phonebook-ldap"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-phonebook-lookup"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-rest-api"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-server-alert"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-simple-autoreply"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-sms-credit"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-sms-member"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-sms-to-email"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-sms-to-twitter"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-sms-to-wordpress"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-sms-to-xmpp"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-soap"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-stop-manager"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-welcome"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-whitelist-number"
},
{
"binary_version": "0.8.3.2-1",
"binary_name": "kalkun-plugin-xmlrpc"
}
]
}