Description
Versions of dojo prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the _testCommon.js and runner.html test files, allowing attackers to execute arbitrary JavaScript in the victim’s browser.
Recommendation
Update the dojo package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.10.0, < 1.10.10 >= 1.11.0, < 1.11.6 >= 1.12.0, < 1.12.4 = 1.13.0** Patched version(s): **1.10.10 1.11.6 1.12.4 1.13.1**
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in dojo - dojo - GHSA-536q-8gxx-m782 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-27gm-ghr9-4v95 - CVE-2020-17480
- Cross-Site Scripting in swagger-ui - swagger-ui - GHSA-7f59-x49p-v8mq - CVE-2016-1000226
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-vrv8-v4w8-f95h - CVE-2020-12648
- Cross-Site Scripting in sanitize-html - sanitize-html - GHSA-3j7m-hmh3-9jmp - CVE-2016-1000237


