XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode
- Severity:
- Medium
Description
Potential XSS vulnerability for users of dojox/xmpp and dojox/dtl.
Recommendation
Update the dojox package to the latest compatible version. Followings are version details:
Affected version(s): **= 1.16.0 >= 1.15.0, < 1.15.2 >= 1.14.0, < 1.14.5 >= 1.13.0, < 1.13.6 >= 1.12.0, < 1.12.7 < 1.11.9** Patched version(s): **1.16.1 1.15.2 1.14.5 1.13.6 1.12.7 1.11.9**
References
Related Issues
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Insufficient Verification of Data Authenticity in Eclipse Theia - CVE-2019-17636
- Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript - CVE-2019-16763
- sanitize-html is vulnerable to XSS through incomprehensive sanitization - CVE-2019-25225
You might also like:
- Tags:
- npm
- dojox
Anything's wrong? Let us know Last updated on January 09, 2023


