Description
XSS possible for users of the Dijit Editor’s LinkDialog plugin
Recommendation
Update the dijit package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.16.0, < 1.16.3 >= 1.15.0, < 1.15.4 >= 1.14.0, < 1.14.7 >= 1.13.0, < 1.13.8 >= 1.12.0, < 1.12.9 < 1.11.11** Patched version(s): **1.16.3 1.15.4 1.14.7 1.13.8 1.12.9 1.11.11**
References
Could your website be exposed too?
SmartScanner can check your website for Cross-site Scripting in dijit editor's LinkDialog plugin and gives you actionable findings to investigate.
Start a free scanRelated Issues
- ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor - CVE-2023-37905
- Cross site scripting in froala-editor - CVE-2020-22864
- dijit editor cross-site scripting vulnerability - CVE-2018-6561
- Pandao Editor.md vulnerable to cross-site scripting (XSS) in iframe src parameter - CVE-2020-19697
You might also like:
See something that needs correcting? Let us knowUpdated March 01, 2023


