DRUPAL-CONTRIB-2022-052

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2022-052

    DRUPAL-CONTRIB-2022-052

    Published: 10 Aug 2022Last Modified: 10 Sept 2026

    Summary:

    Details: jQuery UI is a third-party library used by Drupal. The jQuery UI Checkboxradio module provides the jQuery UI Checkboxradio library (which was previously in Drupal 8 core, but has since been removed from core and moved to this module). As part of the jQuery UI 1.13.2 update, the jQuery UI project disclosed following security issue that may affect sites using the jQuery UI Checkboxradio module: * CVE-2022-31160: [XSS when refreshing a checkboxradio with an HTML-like initial text label](https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9)

    Affected packages

    Package

    Name: drupal/jquery_ui_checkboxradio

    Purl: pkg:composer/drupal/jquery_ui_checkboxradio?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.4.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CONTRIB-2022-052 | CVE-DB