Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
{
"binaries": [
{
"binary_name": "civicrm-common",
"binary_version": "4.7.1+dfsg-2ubuntu1"
},
{
"binary_name": "civicrm-l10n",
"binary_version": "4.7.1+dfsg-2ubuntu1"
},
{
"binary_name": "drupal7-mod-civicrm",
"binary_version": "4.7.1+dfsg-2ubuntu1"
},
{
"binary_name": "wordpress-civicrm",
"binary_version": "4.7.1+dfsg-2ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "kalkun",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-blacklist-number",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-external-script",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-jsonrpc",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-phonebook-ldap",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-phonebook-lookup",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-rest-api",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-server-alert",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-simple-autoreply",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-sms-credit",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-sms-member",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-sms-to-email",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-sms-to-twitter",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-sms-to-wordpress",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-sms-to-xmpp",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-soap",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-stop-manager",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-welcome",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-whitelist-number",
"binary_version": "0.8.3.2-1"
},
{
"binary_name": "kalkun-plugin-xmlrpc",
"binary_version": "0.8.3.2-1"
}
]
}