Description
XSS possible for users of the Dijit Editor’s LinkDialog plugin
Recommendation
Update the dijit package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.16.0, < 1.16.3 >= 1.15.0, < 1.15.4 >= 1.14.0, < 1.14.7 >= 1.13.0, < 1.13.8 >= 1.12.0, < 1.12.9 < 1.11.11** Patched version(s): **1.16.3 1.15.4 1.14.7 1.13.8 1.12.9 1.11.11**
References
- GHSA-cxjc-r2fp-7mq6
- www.oracle.com
- security.netapp.com
- lists.debian.org
- CVE-2020-4051
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor - CVE-2023-37905
- Cross site scripting in froala-editor - CVE-2020-22864
- dijit editor cross-site scripting vulnerability - CVE-2018-6561
- Pandao Editor.md vulnerable to cross-site scripting (XSS) in iframe src parameter - CVE-2020-19697
You might also like:
- Tags:
- npm
- dijit
Anything's wrong? Let us know Last updated on March 01, 2023


