Description
Versions of dojo prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the _testCommon.js and runner.html test files, allowing attackers to execute arbitrary JavaScript in the victim’s browser.
Recommendation
Update the dojo package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.10.0, < 1.10.10 >= 1.11.0, < 1.11.6 >= 1.12.0, < 1.12.4 = 1.13.0** Patched version(s): **1.10.10 1.11.6 1.12.4 1.13.1**
References
- GHSA-536q-8gxx-m782
- bugs.dojotoolkit.org
- www.npmjs.com
- dojotoolkit.org
- secunia.com
- www-01.ibm.com
- www-1.ibm.com
- www.gdssecurity.com
- www.vupen.com
- CVE-2010-2273
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-27gm-ghr9-4v95 - CVE-2020-17480
- Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-7f59-x49p-v8mq - CVE-2016-1000226
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-vrv8-v4w8-f95h - CVE-2020-12648
- Cross-Site Scripting in sanitize-html - sanitize-html - GHSA-3j7m-hmh3-9jmp - CVE-2016-1000237
You might also like:
- Tags:
- npm
- dojo
Anything's wrong? Let us know Last updated on January 09, 2023


