Description
Affected versions of dojo are susceptible to a cross-site scripting vulnerability in the dijit.Editor and textarea components, which execute their contents as Javascript, even when sanitized.
Recommendation
Update the dojo package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.0
- Patched version(s): 1.1.0
References
- GHSA-39cx-xcwj-3rc4
- bugs.dojotoolkit.org
- www.npmjs.com
- exchange.xforce.ibmcloud.com
- trac.dojotoolkit.org
- www.dojotoolkit.org
- www.securityfocus.com
- CVE-2008-6681
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Cross-Site Scripting in dojo - dojo - CVE-2015-5654
- Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782 - CVE-2010-2273
- metascraper before v5.2.0 vulnerable to stored cross-site scripting - CVE-2018-3773
- @claviska/jquery-minicolors vulnerable to Cross-site Scripting - CVE-2021-32850
You might also like:
- Tags:
- npm
- dojo
Anything's wrong? Let us know Last updated on September 27, 2023


