dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
References
Link | Resource |
---|---|
https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr | Exploit Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-DOJOX-548257, | Broken Link |
https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2020-02-13 09:15
Updated : 2020-04-09 06:28
NVD link : CVE-2019-10785
Mitre link : CVE-2019-10785
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
debian
- debian_linux
linuxfoundation
- dojox