Vulnerabilities/

dijit editor cross-site scripting vulnerability

Severity:
Medium

Description

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

Recommendation

Update the dijit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dijit
Anything's wrong? Let us know Last updated on August 28, 2023