dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
References
Link | Resource |
---|---|
https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr | Exploit Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html | Mailing List Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-DOJOX-548257%2C |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2020-02-13 17:15
Updated : 2023-11-07 03:02
NVD link : CVE-2019-10785
Mitre link : CVE-2019-10785
CVE.ORG link : CVE-2019-10785
JSON object : View
Products Affected
debian
- debian_linux
linuxfoundation
- dojox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')