Skip to content

XSS in dijit/editor

Low
dylans published GHSA-cxjc-r2fp-7mq6 Jun 13, 2020

Package

npm dojo/dijit (npm)

Affected versions

<1.11.10, 1.12.0-1.12.8, 1.13.0-1.13.7, 1.14.0-1.14.6, 1.15.0-1.15.3, 1.16.0-1.16.2

Patched versions

1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3

Description

Impact

XSS possible for users of the Dijit Editor's LinkDialog plugin

Patches

Yes, 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3

Workarounds

Users may apply the patch made in these releases.

For more information

If you have any questions or comments about this advisory, open an issue in dojo/dijit

Severity

Low

CVE ID

CVE-2020-4051

Weaknesses

No CWEs

Credits