dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
References
Link | Resource |
---|---|
https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr | Exploit Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html | Mailing List Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-DOJOX-548257%2C | |
https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr | Exploit Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html | Mailing List Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-DOJOX-548257%2C |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 04:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr - Exploit, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html - Mailing List, Third Party Advisory | |
References | () https://snyk.io/vuln/SNYK-JS-DOJOX-548257%2C - |
07 Nov 2023, 03:02
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-02-13 17:15
Updated : 2024-11-21 04:19
NVD link : CVE-2019-10785
Mitre link : CVE-2019-10785
CVE.ORG link : CVE-2019-10785
JSON object : View
Products Affected
debian
- debian_linux
linuxfoundation
- dojox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')