Description
Potential XSS vulnerability for users of dojox/xmpp and dojox/dtl.
Recommendation
Update the dojox package to the latest compatible version. Followings are version details:
Affected version(s): **= 1.16.0 >= 1.15.0, < 1.15.2 >= 1.14.0, < 1.14.5 >= 1.13.0, < 1.13.6 >= 1.12.0, < 1.12.7 < 1.11.9** Patched version(s): **1.16.1 1.15.2 1.14.5 1.13.6 1.12.7 1.11.9**
References
Could your website be exposed too?
SmartScanner can check your website for XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode and gives you actionable findings to investigate.
Start a free scanRelated Issues
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Insufficient Verification of Data Authenticity in Eclipse Theia - CVE-2019-17636
- Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript - CVE-2019-16763
- sanitize-html is vulnerable to XSS through incomprehensive sanitization - CVE-2019-25225
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


