Description
Versions of dojo prior to 1.2.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize HTML code in user-controlled input, allowing attackers to execute arbitrary JavaScript in the victim’s browser.
Recommendation
Update the dojo package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.0
- Patched version(s): 1.9.1
References
- GHSA-p82g-2xpp-m5r3
- cve.mitre.org
- snyk.io
- www.npmjs.com
- jvn.jp
- jvndb.jvn.jp
- www-01.ibm.com
- www.securityfocus.com
- www.securitytracker.com
- CVE-2015-5654
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- DataTable Vulnerable to Cross-Site Scripting - CVE-2015-6584
- Cross-Site Scripting (XSS) in jquery - CVE-2015-9251
- Cross-Site Scripting in handlebars - CVE-2015-8861
- Cross-Site Scripting in dojo - CVE-2008-6681
You might also like:
- Tags:
- npm
- dojo
Anything's wrong? Let us know Last updated on January 06, 2023


