Vulnerability library
Security checkJanuary 09, 2023

Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmdojo

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Versions of dojo prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the _testCommon.js and runner.html test files, allowing attackers to execute arbitrary JavaScript in the victim’s browser.

Recommendation

Update the dojo package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 1.10.0, < 1.10.10 >= 1.11.0, < 1.11.6 >= 1.12.0, < 1.12.4 = 1.13.0**
  • Patched version(s): **1.10.10 1.11.6 1.12.4 1.13.1**

References

Could your website be exposed too?

SmartScanner can check your website for Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782 and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 09, 2023