Description
Affected versions of dojo are susceptible to a cross-site scripting vulnerability in the dijit.Editor and textarea components, which execute their contents as Javascript, even when sanitized.
Recommendation
Update the dojo package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.0
- Patched version(s): 1.1.0
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in dojo and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-Site Scripting in dojo - dojo - CVE-2015-5654
- Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782 - CVE-2010-2273
- metascraper before v5.2.0 vulnerable to stored cross-site scripting - CVE-2018-3773
- @claviska/jquery-minicolors vulnerable to Cross-site Scripting - CVE-2021-32850
You might also like:
See something that needs correcting? Let us knowUpdated September 27, 2023


