Description
Versions of dojo prior to 1.2.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize HTML code in user-controlled input, allowing attackers to execute arbitrary JavaScript in the victim’s browser.
Recommendation
Update the dojo package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.0
- Patched version(s): 1.9.1
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in dojo - dojo and gives you actionable findings to investigate.
Start a free scanRelated Issues
- DataTable Vulnerable to Cross-Site Scripting - CVE-2015-6584
- Cross-Site Scripting (XSS) in jquery - CVE-2015-9251
- Cross-Site Scripting in handlebars - CVE-2015-8861
- Cross-Site Scripting in dojo - CVE-2008-6681


