Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p82g-2xpp-m5r3

Опубликовано: 11 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-Site Scripting in dojo

Versions of dojo prior to 1.2.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize HTML code in user-controlled input, allowing attackers to execute arbitrary JavaScript in the victim's browser.

Recommendation

Upgrade to version 1.2.0 or later.

Пакеты

Наименование

dojo

npm
Затронутые версииВерсия исправления

< 1.2.0

1.9.1

EPSS

Процентиль: 48%
0.00254
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

redhat
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 al ...

EPSS

Процентиль: 48%
0.00254
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79